<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>网络安全观</title>
    <link>https://wechat2rss.xlab.app/feed/e687678d6fc1dacb25e9191fd361250f538e45a1.xml</link>
    <description>网络安全大脑与零信任传道者。睁眼看世界，抬头看战略，低头看产品。研究领域涉及XDR、零信任、身份安全、云安全、数据安全、美国与美军安全体系等。帐号主体为柯善学博士，现任职360。当前，本订阅号只做原创。谢绝商务合作与宣传推广。谢谢关注！&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (网络安全观)</managingEditor>
    <image>
      <url>http://wx.qlogo.cn/mmhead/Q3auHgzwzM4e1ld1FDmRoV5aeBToaO4jmuKhoZ98ibORmicxh5b5Po5Q/0</url>
      <title>网络安全观</title>
      <link>https://wechat2rss.xlab.app/feed/e687678d6fc1dacb25e9191fd361250f538e45a1.xml</link>
    </image>
    <item>
      <title>安全产品终将成为服务</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247495028&amp;idx=1&amp;sn=f37bc36bf24f0018c254b30dabd87cbd</link>
      <description>觉醒</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学</span> <span>2023-02-12 16:15</span> <span style="display: inline-block;">北京</span>
</p>

<p>觉醒</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3a58e2e7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNvqibwhGrF846pAAibh7lloLt5o8krr53f11QQgZEySViaocZsibMjmDCy8Liajbj3c6rI1icVGF0XWkOw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>6千</strong></span>字  <strong>2</strong>图</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t"><p style="text-align: left;margin-top: 8px;"><span style="text-align: left;">本文的重点是讨论</span><strong style="text-align: left;white-space: normal;"><span style="text-align: left;">产品与服务的关系。<span style="text-align: left;"></span></span></strong><span style="text-align: left;"><span style="text-align: left;">产品与服务一直在纠缠之中，既是一对恋人，又是一对冤家。</span></span><span style="text-align: left;">为此，我们将会讲述<strong>一个故事</strong>和<strong>一个模型</strong>。</span></p><p style="text-align: left;margin-top: 8px;"><strong><span style="text-align: left;">一个故事</span></strong><span style="text-align: left;">：<span style="text-align: left;">产品与服务之间有可能产生</span></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>恶性循环</strong></span><span style="text-align: left;"><span style="text-align: left;">，</span>一个知名<span style="text-align: left;">案例就是<strong>FireEye</strong>（硬件大师）和</span><strong>Mandiant</strong>（服务大师）之间<span style="text-align: left;">的网络安全婚姻。在经历了传奇般的结婚和离婚故事后，郎才女貌并没有形成珠联璧合，最终分道扬镳。这也许是因为</span><strong>基因</strong>的差异性根深蒂固<span style="text-align: left;">。</span></span><strong style="text-align: left;white-space: normal;"></strong></p><p style="text-align: left;margin-top: 8px;"><strong style="text-align: left;white-space: normal;">一个模型：</strong>尽管<span style="text-align: left;">FireEye和Mandiant的故事反映了产品与服务之间的不良关系，但这却<strong>并非常态</strong>。</span><span style="color: rgb(172, 57, 255);"><strong><span style="text-align: left;">安全服务飞轮</span></strong></span><span style="text-align: left;">从理论上解释了产品与服务之间的</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>良性循环</strong></span><span style="text-align: left;">，并且</span>表明：<span style="color: rgb(172, 57, 255);"><strong>每个产品终将成为服务</strong></span>，<strong>只要产品活得足够久</strong>。所以，当你发现<strong style="white-space: normal;">EDR供应商成为MDR供应商</strong>、<strong style="white-space: normal;">XDR供应商推出托管XDR</strong>、<strong style="white-space: normal;">SaaS供应商管理自己的SaaS功能</strong>时，请不要奇怪。因为<strong style="white-space: normal;">安全服务飞轮在发挥作用</strong>。安全服务飞轮是一种<strong style="white-space: normal;">永动机</strong>，即使在技术范式发生变化时也能保持服务的价值，从而<strong style="white-space: normal;">使产品供应商转变为服务供应商</strong>以求生存。</p><section style="text-align: left;margin-top: 8px;">360集团创始人<strong>周鸿祎</strong>在《<span style="color: rgb(0, 0, 0);">星空下的对话</span>》中提到的“<span style="color: rgb(172, 57, 255);"><strong>安全服务化</strong><strong>，服务托管化</strong></span>”，与安全服务飞轮的价值主张不谋而合。周鸿祎还提到：360的全部安全服务都将通过云和SaaS化的方式（如360企业安全云）来落地，这既是一种创新模式，也是对安全行业的颠覆式挑战。</section><section style="text-align: left;margin-top: 8px;">安全领导者及其团队需要适应这种转变，逐步消除其心智模型和实施路线图中的<strong>产品与服务孤岛</strong>。</section></section></section></section></section></section><p style="text-align: center;margin-bottom: 0px;margin-top: 24px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></p><section style="margin-top: 8px;"><strong><span style="text-align: left;">1. 恋人还是冤家</span>：<span style="text-align: left;">FireEye(产品)与</span><span style="text-align: left;">Mandiant(服务)的故事</span></strong></section><p style="margin-top: 8px;text-indent: 2em;"><span style="text-align: left;"></span>1）Mandiant和FireEye的联姻寄托了美好希望</p><section style="text-indent: 2em;">2）梦之队的艰难婚姻生活</section><section style="text-indent: 2em;">3）STG：FireEye的收购者</section><section style="text-indent: 2em;">4）Google：Mandiant的收购者</section><section style="text-indent: 2em;">5）预言的兑现：Mandiant和FireEye的未来</section><section style="margin-top: 8px;"><strong>2. 安全服务飞轮<br/></strong></section><section style="margin-top: 8px;"><strong>3. 安全服务飞轮的新变化</strong></section><section style="margin-top: 8px;"><strong>4. 从产品转向服务</strong></section><section style="text-indent: 2em;">1）对甲方（客户方）的好处</section><section style="text-indent: 2em;">2）对乙方（供应商）的好处</section><section style="text-indent: 2em;">3）结束语</section><p style="margin-top: 32px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text"><strong><span style="font-size: 17px;"><strong style="white-space: normal;"><span style="text-align: left;">恋人还是冤家</span>：<span style="text-align: left;">FireEye(产品)与</span><span style="text-align: left;">Mandiant(服务)的故事</span></strong><span style="text-align: left;"></span></span></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><br/></p><p style="margin-top: 8px;">产品与服务一直在纠缠之中，既是一对恋人，又是一对冤家。一个经典案例是<span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">Mandiant和FireEye的网络安全婚姻</span><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">。<strong>关键时间线</strong>如下：</span><span style="background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;"></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">2013年，<strong>FireEye</strong>在</span><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">以</span>10亿美元<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">收购<strong>Mandiant</strong>；</span></span></p></li><li><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">2021年6月，FireEye将其安全产品业务以12亿美元出售给<strong>STG</strong>（Symphony Technology Group）。STG是一家<strong>私募股权巨头</strong>；</span></span></p></li><li><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">2022年1月，STG将<strong>McAfee</strong>企业安全与<strong>FireEye</strong>合并成立新公司，正式命名为<strong>Trellix</strong>，致力于提供<strong>XDR</strong>（<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">扩</span><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">展检测与响应</span>）解决方案；</span></span></p></li><li><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">2022年3月，<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">Google </span>宣布斥资54亿美元收购<strong>Mandiant</strong>，成为<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">Google </span>史上第二大收购案。Mandiant将加入Google Cloud，并保留Mandiant品牌。</span></span></p></li></ul><p style="margin-top: 32px;"><strong><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">1）<strong style="white-space: normal;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">Mandiant和FireEye的联姻</span></strong></span>寄托了美好希望</span></strong></p><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">在婚姻之前，两个团体都分别赢得了他们的声誉：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 8px;"><strong><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">FireEye</span></span></strong><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">：</span>当FireEye在<strong>2013年</strong>以<strong>10亿美元</strong>收购Mandiant时，<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">FireEye</span>还是刚刚IPO成功的网络安全新宠，其股价较IPO首日<strong>暴涨80%</strong>，一跃成为网络安全领域的创新领军企业。当时，<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">FireEye</span>处于安全复兴的前沿，是一家“新型供应商”，采用新方法替代了过去十年的<strong>防病毒</strong>安全供应商。</span></p></li><li><p style="margin-top: 8px;"><strong><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">Mandiant</span></strong><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">：随着<strong>APT1</strong>报告的发布而声名鹊起，并成为少数几家首选的<strong>事件响应</strong>公司之一，对国家参与者的多次入侵做出了回应。</span></p></li><li><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong>美好愿望</strong>：<span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;">FireEye期望</span></span></span></span><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;"></span></span>借助<strong>产品+服务的联姻</strong>，可以构筑无比强大的网络安全</span><strong style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;white-space: normal;">梦之队</strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">。</span></span></p></li></ul><section style="margin-top: 32px;"><strong>2）<strong style="white-space: normal;">梦之队的</strong>艰难婚姻生活</strong><br/></section><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>从第一天就开始了文化冲突</strong>。FireEye和Mandiant的文化从未真正融合。FireEye人员是<strong>硬件</strong>销售大师，而Mandiant 培养了一种<strong>专业和精通</strong>的文化。文化冲突导致梦之队的设想从未实现。而伤害是由于收购后的<strong>人才流失</strong>造成的，导致Mandiant人才散居国外，创办初创公司、经营其他安全公司。FireEye人员以同样的速度退出，并做出同样的事情。</p><section style="margin-top: 8px;"><strong>FireEye的敏锐嗅觉</strong>。FireEye最值得被记住的事情就是：<span style="color: rgb(172, 57, 255);"><strong>FireEye总是能在竞争对手之前采取正确的行动</strong></span>。比如收购Invotas（现为Helix）进军<strong>SOAR</strong>领域，收购Verodin（现称为Mandiant安全验证）进军<strong>BAS</strong>（入侵攻击与模拟）领域，收购Mandiant进军<strong>事件响应</strong>领域。然而，<span style="color: rgb(172, 57, 255);"><strong>仅仅因为在对手之前采取行动，并不能总是成功</strong></span>。正如在所有上述赛道中，FireEye产品从未成为必备品。但反过来看，<span style="color: rgb(172, 57, 255);"><strong>不能总是成功，也并不意味着它们是错误的选择</strong></span>。事实上，FireEye的敏锐嗅觉起到了市场催化剂的作用，促使竞争对手竞相模仿和跟随。<br/></section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>FireEye的产品从未成为必需品</strong>。FireEye的产品组合几乎涵盖整个技术栈的安全硬件，FireEye产品虽然不错但<strong>从未真正取代现有产品</strong>，也始终未能在市场上占据主导地位。比如防火墙仍然存在，而沙箱功能成为它们的一个特性；FireEye的其他产品如TAP和Helix，也从未能替换安全分析或SOAR(安全编排、自动化和响应 ) 领域。在同一时期内，Mandiant的业务表现非常出色（在多项Forrester Wave评估中被列为领导者），但FireEye安全产品在Forrester的评估中表现不佳。</section><section style="margin-top: 8px;"><strong>Mandiant遭受的损失</strong>：Mandiant在其MDR（托管检测和响应）产品和其他安全服务方面，花了很长时间与<strong>“</strong><strong>全FireEye生态”</strong>（all-FireEye ecosystem）绑定在一起（即<strong>排斥其它供应商产品</strong>）。正是因为如此，Mandiant不得不放弃其<strong>事件响应</strong>的声誉，并眼睁睁地看着其竞争对手（主要是针对<span style="color: rgb(172, 57, 255);"><strong>CrowdStrike</strong></span>）在市场估值、股价、客户渗透率方面遥遥领先。最终<strong>Mandiant认识到传统FireEye解决方案阻碍了其业务发展</strong>。</section><section style="margin-top: 8px;"><strong>Mandiant的行动：</strong>Mandiant开始慢慢通过传统服务和软件即服务 (<strong>SaaS</strong>)来 重塑自己。<strong>通过<strong style="white-space: normal;">MDR</strong>（托管检测和响应）、攻击面管理</strong>、<strong style="white-space: normal;">Advantage威胁情报</strong>、<strong>安全验证（即BAS）</strong>及其<strong>传统事件响应</strong>业务等<strong>SaaS产品</strong>找到新动力。</section><p style="margin-top: 32px;"><strong>3）<strong>STG：</strong>FireEye的收购者</strong><br/></p><section style="margin-top: 8px;">STG<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">（Symphony Technology Group）</span>是一家私募股权巨头。到目前为止，<strong>私募股权</strong>对网络安全公司的收购，虽然为安全投资带来了大量活力，但为最终用户带来的创新很少。</section><section style="margin-top: 8px;">无论STG收购<strong style="white-space: normal;">RSA</strong>、<strong>McAfee</strong>、<strong>FireEye</strong>的原因是什么，这些供应商中的<strong>每一个都代表了一个曾经引以为豪的安全品牌</strong>，<span style="color: rgb(172, 57, 255);"><strong>当</strong></span><span style="color: rgb(172, 57, 255);"><strong>这些品牌发现自己未能迁移到云并且转向SaaS时为时已晚</strong></span><strong>，然后眼睁睁地看着自己的市场份额被竞争对手夺走</strong>。</section><section style="margin-top: 8px;">STG收购的资本优势一定是巨大的，否则也没有信心将这些破碎的公司重新组合起来。也许STG计划创建某种网络安全超级团队，要么整合新公司，要么发布新品牌。无论如何，我们都不大可能会记得它是McAfee、RSA、FireEye。</section><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;">最新进展是：2022年1月，STG将<strong>McAfee</strong>企业安全与<strong>FireEye</strong>合并成立新公司，正式命名为<strong>Trellix</strong>，致力于提供<strong>XDR</strong>（<span style="letter-spacing: 0.544px;">扩</span><span style="letter-spacing: 0.544px;">展检测与响应</span>）解决方案。Trellix的名称取自trellis（格架），意为支持植物生长的安全框架。</span></span></p><p style="margin-top: 8px;"><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;"><span style="background-color: rgb(255, 255, 255);">所以，我们真</span>地<span style="background-color: rgb(255, 255, 255);">看不到FireEye了。</span></span></span></p><p style="margin-top: 32px;"><strong>4）<strong style="white-space: normal;">Google：</strong>Mandiant的收购者</strong></p><section style="margin-top: 8px;"><strong>安全实践始于内部零信任项目</strong>。Google的网络安全工作始于2011年发起的<strong style="white-space: normal;">BeyondCorp（零信任项目）</strong>、2014年发起的<strong>Project Zero</strong>（旨在应对“<strong>零日漏洞</strong>”威胁）等<strong>内部安全项目</strong>。</section><section style="margin-top: 8px;"><strong style="white-space: normal;">网络安全商业</strong><strong style="white-space: normal;">化较晚。</strong>2012年Google对<span style="color: rgb(172, 57, 255);"><strong>VirusTotal</strong></span>的收购可能表明谷歌对<strong>网络安全商业</strong><strong>化</strong>的兴趣。但GCP（谷歌云）转向以企业为中心的商业能力的确有些晚，Google的<strong>X计划</strong>于2018年推出Chronicle，GCP于2019年收购它。</section><section style="margin-top: 8px;"><strong>起步较晚只能买买买</strong>。谷歌和微软在企业业务上展开了广泛的竞争，两者都表示，将在未来<strong>五年内花费超过</strong><span style="color: rgb(172, 57, 255);"><strong>100亿美元</strong></span><strong>发展网络安全</strong>。起步较晚需要溢价才能赶上。谷歌在2022年1月就收购了<strong>Siemplify</strong>（<strong>SOAR</strong>提供商）。2022年3月耗资54亿美元对Mandiant的收购，<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">成为</span><span style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">Google </span><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">史上第二大收购案。</span>收购Mandiant，不仅能够补充Google Cloud在安全方面的现有优势，还将增强谷歌的安全运营套件和咨询服务，为其带去由包括600多名安全顾问和300多名情报分析师组成的网络安全精英。</section><section style="margin-top: 8px;"><strong>开启网络安全发现新时代</strong>。GCP希望成为一流的网络安全公司。借助<strong>Mandiant</strong>的事件响应专业知识，再加上<strong>VirusTotal</strong><strong>数据</strong>和Project Zero项目的人才，随着两个团队的合作，可能会开启一个网络安全发现新时代。</section><p style="margin-top: 32px;"><strong><strong style="white-space: normal;">5）预言的兑现：Mandiant和<strong style="white-space: normal;">FireEye</strong></strong>的未来</strong></p><section style="margin-top: 8px;"><strong><strong style="white-space: normal;">2021年6月，<strong style="white-space: normal;">Forrester副总裁兼首席分析师</strong></strong></strong>Jeff Pollard（正是提出“<strong>安全服务飞轮</strong>”概念之人）在其博客中预测了Mandiant和FireEye的未来：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong>Mandiant ：将受益于其收购方的剥离</strong>。Mandiant似乎能够<strong>通过</strong><span style="color: rgb(172, 57, 255);"><strong>精简</strong></span><strong>自身来继续其前进势头</strong>。从FireEye中的拆分，还将使Mandiant能够继续利用其<strong>情报驱动的服务</strong>并发展<strong>MDR业务</strong>。通过更多地监控和管理<strong>任意供应商</strong>的安全产品，网络威胁情报团队将受益于对全球威胁形势的更高可见性。这一次性消除了Mandiant的所有偏见。</section></li><li><section style="margin-top: 8px;"><strong>FireEye</strong>：当然也会受益于STG的财大气粗。但风险在于，它会与STG的另外两大网络安全“<strong>过时品牌</strong>”（McAfee 、RSA）进行合并。尽管FireEye确实大放异彩。然而，<strong>在一支糟糕的球队中成为最好的球员，仍然意味着你会输掉大部分比赛</strong>。而且到目前为止，PE（私募股权）对网络安全公司的收购，虽然为投资者带来了大量活力，但为最终用户带来的创新很少。</section></li><li><section style="margin-top: 8px;"><span style="color: rgb(172, 57, 255);"><strong>预言</strong></span>：Jeff Pollard在<strong>2021年6月</strong>的博客中预测，<strong>五年后</strong>，<strong>Mandiant将成为一个知名度很高的安全品牌</strong>；<strong>而FireEye可能会被淹没历史的车轮中</strong>。这毫无疑问反映出他对安全服务的看好。</section></li><li><section style="margin-top: 8px;"><strong>预言的兑现</strong>：自2021年6月至今（2023年2月），还没到两年的时间，却已经出现了新的结果：<strong style="white-space: normal;">FireEye</strong>确实已经融入到一家新公司Trellix中开启<span style="color: rgb(172, 57, 255);"><strong>XDR</strong></span>之路，但已然<strong>失去了独立品牌</strong>；而<strong>Mandiant</strong>则融入到GCP中，准备大放<span style="color: rgb(172, 57, 255);"><strong>MDR</strong></span>异彩，并且<strong>保留了独立品牌</strong>。他们的选择或许都是恰当的，也为我们留下了宝贵的启示。<strong style="white-space: normal;"></strong><br/></section></li></ul><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text"><strong><span style="font-size: 17px;">安全服务飞轮</span></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><br/></p><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">在前面<span style="text-align: left;">FireEye(产品)与</span><span style="text-align: left;">Mandiant(服务)的故事中，反映了<strong>盒子大师与服务大师之间的较量</strong>。而<strong>Forrester副总裁兼首席分析师</strong>Jeff Pollard的偏好无疑是站在Mandiant安全服务这一边的。</span></p><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><span style="text-align: left;"></span></section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><span style="text-align: left;">另外，FireEye(产品)与Mandiant(服务)的故事似乎反映了<strong>产品与服务之间的恶性循环</strong>（或许是缘于基因/文化的原因）。但<strong>Forrester副总裁兼首席分析师</strong>Jeff Pollard提出的<strong>安全服务飞轮</strong>概念，却完美地诠释了<strong>产品与服务之间的良性循环</strong>。</span></section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">“<strong>安全服务飞轮</strong>”（Security Services Flywheel）是<strong>Forrester副总裁兼首席分析师</strong>Jeff Pollard在第一次加入Forrester时创造的概念。</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>机械飞轮</strong>：在机械工程中，飞轮实际上是一个储存动能的轮子，是拖拉机、蒸汽机、脚踏缝纫机运转的关键。<br/></section></li><li><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>业务飞轮</strong>：当将<strong>飞轮概念应用于业务</strong>时，它通常表示公司不同的组成部分建立起不可阻挡的动力。关键点在于：飞轮的步骤不能只是企业不同部分的单独行动。它们必须<strong>在因果关系中相互引导</strong>。</section></li><li><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>安全服务飞轮</strong>：解释了为什么安全服务能持续保持价值，无论产品变得多么复杂。</section></li><li><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong style="white-space: normal;">安全服务</strong><strong>飞轮</strong><strong>的要点</strong>很简单：<strong>产品供应商承诺过多而交付不足</strong>。当用户发现交付问题时，通常为时已晚。他们购买的每件产品都会发生这种情况，只好求助于服务来解决未达到的期望。</section></li></ul><p style="margin-bottom: 0px;white-space: normal;margin-top: 16px;"><img class="rich_pages wxw-img" data-ratio="0.6924167257264352" data-w="1411" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=45bc9eef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNvqibwhGrF846pAAibh7lloLmQoJrMlUxADicOrSSYc8jSdFEXkrKUIWLsaehZtztiaohTuWCibddyngg%2F640%3Fwx_fmt%3Dpng"/><br/></p><p style="margin-bottom: 0px;white-space: normal;margin-top: 16px;text-align: center;">图1-安全服务飞轮</p><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>安全服务飞轮的循环：</strong></section><ol class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 8px;"><strong>新产品出现</strong>：由于存在产品市场的匹配，新产品获得市场份额。</section></li><li><section style="margin-top: 8px;"><strong>专业服务出现</strong>：产品售卖给客户后，客户的<strong>采用问题</strong>出现了，因为客户发现：部署和实施新产品给他们带来了挑战。这些采用难题导致了部署和集成<strong>专业服务</strong>的出现，这些专业服务通过产品供应商的<strong>服务合作伙伴</strong>来提供。</section></li><li><section style="margin-top: 8px;"><strong>MSS出现</strong>：当客户的采用问题被解决之后，产品的<strong>日常运营</strong><strong>问题</strong>又变得令人头疼，于是<strong>第三方</strong><strong>MSS（托管安全服务）</strong>被引入进来。</section></li><li><section style="margin-top: 8px;"><strong>SaaS出现</strong>：接下来，“<strong>产品</strong>”逐渐变成了一种<strong>服务</strong>：软件即服务(<strong>SaaS</strong>)！这时，客户不再需要维护它了，是吗？<strong>不</strong>。<strong>SaaS只是由其他人在其他地方托管的产品</strong>，它仍然需要悉心照料。</section></li><li><section style="margin-top: 8px;"><strong>托管型SaaS出现</strong>：这才是SaaS产品功能和效果真正得到妥善管理的地方。</section></li></ol><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">这个飞轮循环虽然特定于网络安全领域，但也适用于其他领域的产品和服务。飞轮循环可以一路验证回到防火墙和SIEM（安全信息与事件管理）。</section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>先以防火墙为例：</strong></section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 8px;">首批防火墙在20世纪90年代初期和中期获得了认可和市场份额。</section></li><li><section style="margin-top: 8px;">增值经销商和集成商前来安装它们。</section></li><li><section style="margin-top: 8px;">1990年代中后期出现了第一批托管安全服务(MSS)提供商。</section></li></ul><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><strong>再以SIEM（安全信息与事件管理）为例：</strong></section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 8px;">早期的SIEM出现于2000年代中期；</section></li><li><section style="margin-top: 8px;">实施SIEM的专业服务出现；</section></li><li><section style="margin-top: 8px;">新一轮的托管安全服务(MSS)提供商出现，其他人将其添加到服务组合中。</section></li></ul><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">安全服务飞轮在历史上持续发挥作用：每一个出现的产品都<strong>需要</strong><span style="color: rgb(172, 57, 255);"><strong>专业服务</strong></span><strong>来实施，需要</strong><span style="color: rgb(172, 57, 255);"><strong>托管安全服务</strong></span><strong>来运行，最终采取</strong><span style="color: rgb(172, 57, 255);"><strong>托管SaaS</strong></span><strong>的方式</strong>（如果产品能够存在足够长的时间）。</section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">但是，安全服务飞轮也并非一成不变，我们接下来看看它的新变化。</section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text"><strong><span style="font-size: 17px;">安全服务飞轮的新变化</span></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;"><br/></p><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">现在，安全服务飞轮的主要变化在于<strong>供应商不再依赖这些服务的合作伙伴关系</strong>，而是几乎立即推出了自己的<strong>托管安全SaaS服务</strong>。这种情况最近在<strong>EDR</strong>（端点检测和响应）领域中显现，并在<strong>XDR</strong>（扩展检测和响应）领域中实时发生。</p><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">从历史上看，产品供应商会与服务提供商合作来提供服务，并且在推出自己的服务之前会等待很长时间，或者根本不会推出服务。而在最近的历史中，<strong>这种差距从几年缩短到几个月，而到2022年几乎消失了</strong>。供应商在发布新产品的同时，就会将其产品的<strong>完全托管版本</strong>推向市场。</section><section style="margin-top: 8px;margin-bottom: 0px;white-space: normal;">下面，<span style="font-size: 17px;">以<span style="font-size: 17px;">EDR和XDR领域为例</span></span>，我们来看看<strong style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><span style="font-size: 17px;">安全服务飞轮的新变化：</span></strong></section><p class="js_pay_preview_filter"><mp-pay-preview-filter></mp-pay-preview-filter></p>



<p><a href="2247495028">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=cd68a379&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247495028%26idx%3D1%26sn%3Df37bc36bf24f0018c254b30dabd87cbd%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 12 Feb 2023 16:15:00 +0800</pubDate>
    </item>
    <item>
      <title>中国的网空能力</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247495018&amp;idx=1&amp;sn=d30e74ae9155e759d3491e7ab3827bdf</link>
      <description>反方视角</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学</span> <span>2023-02-01 13:55</span> <span style="display: inline-block;">北京</span>
</p>

<p>反方视角</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f8a14b03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPOgbQwWkbycYWb9Od3Bvpumkgo8vIPMMBERyhqictN46uuIE9o4LqoQLfcia0ulEoCsmXwf6jPAknkQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>6千</strong></span>字</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t"><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;">如果想知道<strong>美国如何看待ZG的网络空间能力</strong>，最佳资料当属2022年11月美国<strong>国会</strong>下属机构<strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">美中经济和安全审查委员会</span></strong>发布的《<strong>致<span style="text-align: left;">国会</span>2022<span style="text-align: left;">年度报告</span></strong>》。该报告接近800页，其中有一节（<span style="text-align: left;">第3章第2节</span>）</span><span style="font-size: 17px;">《<strong style="text-align: left;white-space: normal;">ZG的网络（<strong style="color: rgb(172, 57, 255);text-align: left;white-space: normal;">Cyber </strong>）能力</strong>》，专门论述了<strong>ZG的</strong><span style="color: rgb(172, 57, 255);"><strong>进攻性</strong></span><strong>网络能力</strong>。别小看这一节！它的篇幅是<strong>101页</strong>。</span></p><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;"><span style="text-align: left;">《</span><strong style="text-align: left;white-space: normal;">ZG的网络能力</strong><span style="text-align: left;">》报告认为：“在过去的十年中，ZG大规模增强了其网络能力，并在今天的网络空间中对美国构成了<strong>巨大威胁</strong>。<span style="text-align: left;">” </span></span>报告从三大方面来阐述ZG如何实现<strong>十年跨越式发展</strong>：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="text-align: left;margin-top: 0px;"><span style="font-size: 17px;"><strong><span style="text-align: left;">重组网络决策机构</span></strong><span style="text-align: left;">：对应于组织调整，这是顶层设计；</span></span></section></li><li><section style="text-align: left;margin-top: 0px;"><span style="font-size: 17px;"><strong><span style="text-align: left;">发展先进的网络战能力</span></strong><span style="text-align: left;">：</span><span style="text-align: left;">以</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>SSF</strong></span><span style="text-align: left;">为代表；</span></span></section></li><li><section style="text-align: left;margin-top: 0px;"><span style="font-size: 17px;"><strong><span style="text-align: left;">实施网络<strong style="text-align: left;white-space: normal;">情报</strong>活动</span></strong><span style="text-align: left;">：</span><span style="text-align: left;">以</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>MSS</strong></span><span style="text-align: left;">为代表。</span></span></section></li></ul><p style="text-align: left;margin-top: 8px;"><span style="text-align: left;font-size: 17px;">作为对比，在2021年的美国国际战略研究所（IISS）的评估报告《网络能力与国家实力：净评估》中，将ZG作为<strong>第2梯队</strong>国家看待。而这一次，明显更进一步，将ZG不仅仅是作为第2梯队，而是作为<strong>第2名</strong>看待，甚至为ZG是否美国的<strong>匹敌对手</strong>而争论。</span></p><p style="text-align: left;margin-top: 8px;"><span style="text-align: left;font-size: 17px;">报告在大谈ZG网络能力突飞猛进的同时，也列出了<strong>四点不足</strong>：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="font-size: 17px;"><p style="text-align: left;"><span style="font-size: 17px;">缺乏网络战理论和经验；</span></p></li><li style="font-size: 17px;"><p style="text-align: left;"><span style="font-size: 17px;">缺乏横向信息拉通；</span></p></li><li style="font-size: 17px;"><p style="text-align: left;"><span style="font-size: 17px;">无法高效运用预备役；</span></p></li><li style="font-size: 17px;"><p style="text-align: left;"><span style="font-size: 17px;"><span style="text-align: left;">国内</span>整体网络安全能力依然薄弱。</span></p></li></ul><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;"></span>从立场的角度看，这是一次<strong>大反派</strong>的呐喊和宣泄，也是一次<strong>集中</strong><strong>爆料</strong>。其中穿插了许多历史安全事件和人物，涉及不少国内安全公司、院校、科研机构。其中<strong>出现最多的是</strong><span style="color: rgb(172, 57, 255);"><strong>360</strong></span><strong>公司，不少于11次</strong>，这当然是因为<strong>360最具备对美方网络攻击活动的披露能力</strong>。</p><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;">英文原文的下载地址：<br/></span></p><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;"><a href="https://www.uscc.gov/annual-report/2022-annual-report-congress" target="_blank">https://www.uscc.gov/annual-report/2022-annual-report-congress</a></span></p><p style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;">在本文末尾，也直接给出了<strong>英文原文（PDF版）</strong>和</span><span style="font-size: 17px;color: rgb(0, 0, 0);"><strong>付费</strong></span><span style="font-size: 17px;"><strong>机器翻译中文版（Word版）</strong>的下载方式，但需</span><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>付费</strong></span><span style="font-size: 17px;">查看。</span></p></section></section></section></section></section><p style="text-align: center;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="15.470533208606174" data-s="300,640" style="" data-type="jpeg" data-w="1069" src="https://wechat2rss.xlab.app/img-proxy/?k=69f91cf8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPMBvXaK99fx5KhsUheudgfpEA4iaGG8In6S8kxkSy7jh5hxibSfohAHmoOb8mljc5TN8XgeBPfIxrCQ%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><span style="font-size: 17px;text-align: left;"></span></p><p class="js_pay_preview_filter"><mp-pay-preview-filter></mp-pay-preview-filter></p>



<p><a href="2247495018">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e2cbcf01&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247495018%26idx%3D1%26sn%3Dd30e74ae9155e759d3491e7ab3827bdf%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Feb 2023 13:55:00 +0800</pubDate>
    </item>
    <item>
      <title>美军进攻性网络作战架构</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494981&amp;idx=1&amp;sn=4e6ef7993457cd573c65c36c5d5f7462</link>
      <description>网络作战平台的天选之子</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学</span> <span>2022-11-27 15:29</span> <span style="display: inline-block;">北京</span>
</p>

<p>网络作战平台的天选之子</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a7d694fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPPtvnk7HT7pmQaK6hyqnS4ib9WVcsXTCwBggNial9iciaiaTXIhDJjV8cCibCscuM7USqWI5cA6qRTZJtqg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>7500</strong></span>字  <strong>17</strong>图  阅读约<span style="color:#000000;"><strong>20</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t"><p style="text-align: left;margin-top: 8px;">通常认为，<strong>网络攻击</strong>是一种&#34;<strong>小作坊</strong>&#34;的工作方式，从来不觉得它与高大上有何关联。但是，美军就真地把它变得高大上了。</p><p style="text-align: left;margin-top: 8px;">自<strong><span style="color: rgb(0, 0, 0);">2018</span>年</strong>来，美国<strong>网络司令部</strong>尝试建立&#34;<strong>正规军</strong>&#34;的网络作战方式——<strong>联合网络作战架构（JCWA）</strong>。但遗憾的是，我们对美国国防部的进攻性网络作战架构，难以有深入的了解。因为进攻性网络作战的领导者是网络司令部，它的前身是NSA（国家安全局），这两个部门都是出了名的嘴巴严，很少透露深度资料。<br/></p><p style="text-align: left;margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">但嘴巴再严，也有被迫张开嘴的时候。特别是在GAO（<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline !important;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;">政府问责</span></strong></span><span style="color: rgb(0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">局</span></span></strong>）的审计要求下，它不得不透露更多的信息；而在一些国防部对外采购会议上，它也不得不展示一些细节。这也使得我们看到了一些真面目。虽然不多，但胜于无。</span></p><p style="text-align: left;margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">不论<strong>网络攻击</strong>，还是<strong>网络</strong><strong>防御</strong>，都有两个共性难题：一是<strong>时间（效率）</strong>，二是<strong>空间（规模）</strong>。而解决之道，唯有<strong>自动化</strong>。放在<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">防御领域，就是</span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(172, 57, 255);display: inline !important;"><strong>安全自动化</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">；放在攻击领域，就是</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(172, 57, 255);display: inline !important;"><strong>攻击自动化</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">。<br/></span></p><p style="text-align: left;margin-top: 8px;"><strong>很多人曾经认为</strong>：美国国防部（由DISA主导）以<span style="color: rgb(172, 57, 255);"><strong>急先锋</strong></span><strong>姿态</strong>推进的<strong>零信任架构<strong>（ZTA）</strong></strong>是一种虚张声势！但现实是：美国<strong>国家级别</strong>的<strong>联邦政府零信任战略</strong>已经颁布；美国<strong>国防部级别</strong>的<strong>零信任战略</strong>和<strong>零信任参考架构</strong>已经发布；国防部的<strong>零信任试点项目</strong>（雷霆穹顶）正在加速推进。<br/></p><p style="text-align: left;margin-top: 8px;"><strong>很多人仍然认为</strong>：美国国防部（由网络司令部主导）以<span style="color: rgb(172, 57, 255);"><strong>颠覆者</strong></span><strong>姿态</strong>推出的<strong>联合网络作战架构<strong style="text-align: left;white-space: normal;">（JCWA）</strong></strong>是一种虚张声势！但现实是：该架构的所有<strong>六大支柱型产品</strong>均已具备交付能力，正在按照<strong style="text-align: left;white-space: normal;">推进时间表</strong>有序迭代。</p><p style="margin-top: 8px;margin-bottom: 0px;white-space: normal;text-align: left;">我们当然可以怀揣着阿Q精神/精神胜利法，继续对自己小作坊式的攻击方式感到沾沾自喜，但请不要对美军的集团军式的网络作战架构掉以轻心。</p></section></section></section></section></section><p><strong>关键词</strong>：<strong>JCWA</strong>（联合网络作战架构，Joint Cyber Warfighting Architecture）；<strong>UP</strong>（统一平台，Unified Platform）；<strong>JCC2</strong>（联合网络指挥与控制，Joint Cyber Control and Command）；<strong>JCAP</strong>（联合通用访问平台，Joint Common Access Platform）；<strong>PCTE</strong>（持续网络演训环境，Persistent Cyber Training Environment）；<strong>JADC2</strong>（联合全域指挥与控制，Joint All-Domain Command and Control）；<strong>GAO</strong>（政府问责局，Government Accountability Office）；</p><section style="text-align: center;margin-top: 15px;margin-bottom: 0px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;">1. 网络司令部的<strong>创新战略</strong><br/></p><p>2. What：JCWA<strong>是什么</strong>？<br/></p><section style="text-indent: 2em;">2.1 JCWA是什么？</section><section style="text-indent: 2em;"><span style="text-indent: 34px;">2.</span>2 JCWA的体系组成图</section><section style="text-indent: 2em;"><span style="text-indent: 34px;">2.</span>3 JCWA的<strong>六大支柱</strong></section><p>3. Why：<strong>为什么</strong>要开发JCWA？</p><section style="text-indent: 2em;">3.1 JCWA的<strong>根因</strong>是网络司令部要独立</section><section style="text-indent: 2em;">3.2 为什么<strong>情报工具</strong>和<strong>作战工具</strong>必须分开</section><section style="text-indent: 2em;">3.3 JCWA成为<strong>作战工具</strong>的天选之子</section><p style="margin-bottom: 0px;white-space: normal;">4. How：<span style="text-indent: 34px;">JCWA的<strong>运行机理</strong></span></p><section style="margin-bottom: 0px;white-space: normal;text-indent: 2em;"><span style="text-indent: 2em;">4.1 JCWA在网络司令部使命中的定位</span><br/></section><section style="margin-bottom: 0px;white-space: normal;text-indent: 2em;">4.2 JCWA的运行机理</section><section style="margin-bottom: 0px;white-space: normal;text-indent: 2em;">4.3 JCWA<strong>如何用于网络作战</strong></section><section style="margin-bottom: 0px;white-space: normal;text-indent: 2em;">4.4 值得深究的<span style="text-indent: 34px;">JCWA</span><strong>传感器</strong></section><p>5. How：<strong>如何推进</strong>JCWA建设工作？</p><section style="margin-bottom: 0px;white-space: normal;text-indent: 2em;"><span style="text-indent: 2em;">5.1 JCWA的建设预算</span><br/></section><section style="text-indent: 2em;">5.2 JCWA的建设进度</section><section style="text-indent: 2em;">5.3 对JCWA的评估情况</section><p><br/></p><p style="margin-bottom: 0px;white-space: normal;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">网络司令部的创新战略</span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 8px;"><br/></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 8px;"><span style="font-size: 17px;">网络司令部在2022年8月的一次<span style="text-align: left;">对外采购会议PPT上展示了它</span>的创新战略。</span></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">网络司令部<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">创新战</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">略的</span></span>目的</strong>：建立并培养一种鼓励和奖励<strong>创新思维</strong>和<strong>冒险精神</strong>的文化。</section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><strong style="white-space: normal;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">网络司令部创新战略的</span></strong>目标</strong>：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;">开发一个<strong>框架</strong>，在我们最具挑战性的问题上实现协作，并展示前所未有的能力和大幅提高的效率。</section></li><li><section style="margin-top: 8px;">将投资投入到相关的、前瞻性的<strong>概念</strong>上，以创造能力优势，同时获得切实的、重大的任务成功。</section></li><li><section style="margin-top: 8px;">扩大网络创新团体的规模、专业性、影响力；让<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">网络司令部</span>成为<span style="color: rgb(172, 57, 255);"><strong>思想领袖</strong></span>——“<strong>塑造网络空间作战的未来</strong>”。</section></li></ul><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">网络司令部还</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">引用了下面的</span><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">创新类型矩阵图</strong><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">：</span></section><p style="margin-bottom: 0px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-backh="399" data-backw="409" data-ratio="0.97669256381798" style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;width: 100%;height: auto;" data-type="png" data-w="901" src="https://wechat2rss.xlab.app/img-proxy/?k=29e42099&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNRuqm5GNRrWhOIMOejQQPJg3OlANIKCfMbS8s0niasBdMRKhtN0hBl9BzJJhia1I8eMNGwAQfQicD8A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;text-align: center;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">图1-创新频谱</span></p><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;">这个<span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">创新频谱</span>并没有什么稀罕的，而真正令我稀罕的是网络司令部随后展示的这张图：<br/></section><p style="margin-bottom: 0px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.6842800528401585" data-w="1514" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3956257a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNRuqm5GNRrWhOIMOejQQPJXBXHxQLTJpH7ghpw1oe2ibn2P1HicIf11sYKgcW6H97w5JRDkngBibrZA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-bottom: 0px;white-space: normal;text-align: center;">图2-网络司令部的持续创新：跨越创新频谱<br/></p><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;">笔者对此图的理解是：<br/></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong><span style="text-align: center;">“跨越创新频谱<strong style="white-space: normal;"><span style="text-align: center;">”</span></strong></span></strong><span style="text-align: center;">之含义：是指4种类型的创新（图中最右侧）都需要；</span></section></li><li><section style="margin-top: 8px;"><strong><span style="text-align: center;">“转折点<strong style="white-space: normal;"><span style="text-align: center;">”</span></strong></span></strong><span style="text-align: center;"><span style="text-align: center;">之</span>含义：是指如果缺少<strong>颠覆型创新</strong>，就不可能在能力上超越网络对手。原因何在？因为敌手的能力是<strong>指数性增长</strong>的（即图中的</span><span style="text-align: center;color: rgb(255, 0, 0);">红色</span><span style="text-align: center;">曲线），而增量型<span style="text-align: center;">创新</span>、进化型<span style="text-align: center;">创新</span>、彻底型创新都是<strong>线性增长</strong>的（<span style="text-align: center;">即图中的</span></span><span style="color: rgb(0, 82, 255);">蓝色</span><span style="color: rgb(0, 0, 0);">直</span><span style="text-align: center;"><span style="text-align: center;">线</span>），仅靠这些类型的创新永远追赶不上敌手的能力；而<strong style="text-align: center;white-space: normal;">颠覆型创新</strong>才具有<strong>指数性增长</strong>的潜能（即<span style="text-align: center;">图中的</span></span><span style="color: rgb(61, 167, 66);">绿色</span><span style="text-align: center;"><span style="text-align: center;">曲线</span>），所以它也是唯一的希望。</span></section></li></ul><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;">问题来了：网络司令部的<strong style="text-align: center;">颠覆型创新是指什么呢？</strong>毫无疑问，正是<strong style="text-align: center;"><strong style="text-align: left;">联合网络作战架构（JCWA）</strong></strong>！</section><section style="text-align: left;margin-bottom: 0px;margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: center;"><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">What：</span></strong></span></strong></span></strong></strong></strong></strong>JCWA是什么？</span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 8px;"><br/></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 34px;background-color: rgb(255, 255, 255);">2.1 </span>JCWA是什么？</strong></section><section style="margin-top: 8px;">JCWA是网络空间<strong>进攻</strong>领域的<strong>作战架构</strong>：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;">JCWA是一个<strong>能力套件</strong>；</section></li><li><section style="margin-top: 8px;"><strong>数据整合</strong>：JCWA整合了<strong>进攻性</strong>数据和<strong>防御性</strong>数据；</section></li><li><section style="margin-top: 8px;"><strong>作用领域</strong>：JCWA涵盖竞争、危机、冲突领域；</section></li><li><section style="margin-top: 8px;"><strong>目标</strong>：JCWA使得指挥官能够</section></li></ul><section style="text-indent: 2em;margin-top: 8px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:等线;mso-fareast-theme-font:minor-fareast;mso-ansi-language:EN-US;mso-fareast-language:
ZH-CN;mso-bidi-language:AR-SA;"><span lang="EN-US" style="font-family: &#34;Times New Roman&#34;, serif;">●</span>  </span>衡量<strong>风险</strong>；</section><section style="text-indent: 2em;margin-top: 8px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:等线;mso-fareast-theme-font:minor-fareast;mso-ansi-language:EN-US;mso-fareast-language:
ZH-CN;mso-bidi-language:AR-SA;"><span lang="EN-US" style="font-family: &#34;Times New Roman&#34;, serif;">●</span>  </span>及时做出<strong>决策</strong>；</section><section style="text-indent: 2em;margin-top: 8px;"><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:
11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:等线;mso-fareast-theme-font:minor-fareast;mso-ansi-language:EN-US;mso-fareast-language:
ZH-CN;mso-bidi-language:AR-SA;"><span lang="EN-US" style="font-family: &#34;Times New Roman&#34;, serif;">●</span>  </span>以<strong>足够快的</strong><span style="color: rgb(172, 57, 255);"><strong>速度</strong></span><span style="text-indent: 34px;">（<em>时间维度</em>）</span>和<strong>足够大的</strong><span style="color: rgb(172, 57, 255);"><strong>规模</strong></span><span style="text-indent: 34px;">（<em>空间维度</em>）展开</span><strong>行动</strong>。（<em>笔者注：</em><em>这一条正是笔者认为国防部努力实现<span style="color: rgb(172, 57, 255);"><strong>攻击自动化</strong></span>的佐证。</em>）</section><section style="margin-bottom: 0px;white-space: normal;text-align: left;margin-top: 8px;"><em><strong><span style="text-align: left;">笔者的观点：</span></strong><span style="text-align: left;">JCWA的</span><strong><span style="text-align: left;">关键要求</span></strong><span style="text-align: left;">是</span><strong style=""><span style="text-align: left;"><strong style="white-space: normal;"><span style="color:#ac39ff;">互操作性</span></strong></span></strong><span style="text-align: left;">、</span><strong><span style="text-align: left;color: rgb(172, 57, 255);"><strong>集成性</strong></span></strong></em><span style="color: rgb(0, 0, 0);"><em><span style="text-align: left;">、</span></em></span><em><strong><span style="text-align: left;color: rgb(172, 57, 255);"><strong>自动化</strong></span></strong><span style="text-align: left;">，</span><strong><span style="text-align: left;">核心目标</span></strong><span style="text-align: left;">是实现</span></em><span style="color: rgb(172, 57, 255);"><em><span style="text-align: left;"><strong>网络</strong></span></em></span><em><strong><span style="text-align: left;"><em style="text-indent: 34px;white-space: normal;"><span style="color: rgb(172, 57, 255);"><strong>攻击自动化</strong></span></em></span></strong></em><span style="color: rgb(0, 0, 0);"><em><span style="color: rgb(0, 0, 0);text-align: left;">。</span></em></span></section><section style="margin-bottom: 0px;white-space: normal;text-align: left;margin-top: 8px;"><strong><span style="text-align: left;">JCWA是一种企业架构</span></strong><span style="text-align: left;">。</span>与国防部（DoD）和情报界（IC）的<strong style="white-space: normal;">企业观</strong>一致，网络司令部将联合网络作战架构（JCWA）视作一种<strong style="white-space: normal;">企业方法</strong>。网络司令部的执行主任称“就像任何公司企业都会考虑如何管理广泛的业务一样，我们将网络司令部视为一个企业，而联合部队总部也是该企业的一部分。”联合网络作战架构（JCWA）正是这样一种<span style="color: rgb(172, 57, 255);"><strong>企业作战架构</strong></span>。当然，JCWA的五大不同组件可以在统一架构之下由不同军种开发，比如统一平台（UP）由空军开发，联合网络指挥和控制（JCC2）系统由陆军开发。</section><section style="margin-bottom: 0px;white-space: normal;text-align: left;margin-top: 8px;"><br/></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><strong style="white-space: normal;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 34px;background-color: rgb(255, 255, 255);">2.2 </span></strong>JCWA的体系组成图</strong></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.6361058601134215" style="text-align: center;" data-type="png" data-w="1058" src="https://wechat2rss.xlab.app/img-proxy/?k=8e106c20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNRuqm5GNRrWhOIMOejQQPJvayISeBz6hrWlN4o1icoznatW5iaFG6K4tSqibhMyXs2jWViaOyekRh8Ew%2F640%3Fwx_fmt%3Dpng"/></section><p style="margin-top: 10px;margin-bottom: 0px;white-space: normal;text-align: center;">图3-JCWA的组成<br/></p><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><br/></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><strong style="white-space: normal;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 34px;background-color: rgb(255, 255, 255);">2.3 </span></strong>JCWA的六大支柱</strong></section><section style="margin-top: 8px;">如上图所示，联合网络作战架构（JCWA）包括五个组成部分：</section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 8px;"><strong>统一平台</strong>（<strong>UP</strong>，Unified Platform）：是JCWA的<span style="color: rgb(172, 57, 255);"><strong>大</strong><strong>数据分析平台</strong></span>，负责数据管理和集成，目的是为网络作战人员和支撑人员提供数据同步和系统访问。它被认为是摄取、分析、共享数据的核心。<br/></section></li><li><section style="margin-top: 8px;"><strong>联合网络指挥与控制</strong>（<strong>JCC2</strong>，Joint Cyber Control and Command）系统：是<span style="color: rgb(172, 57, 255);"><strong>决策平台</strong></span>，目标是整合来自多个来源的态势感知数据，以支持指挥官的作战决策；旨在战略、战役、战术各个层面增强美军网络空间作战的<strong>态势感知</strong>和<strong>战斗管理</strong>，从而加强网络指挥和控制，提升联合作战效能。</section></li><li><section style="margin-top: 8px;"><strong>联合通用访问平台</strong>（<strong>JCAP</strong>，Joint Common Access Platform）：是<span style="color: rgb(172, 57, 255);"><strong>任务执行平台</strong></span>，目的是为美军网络空间作战部队提供一个通用的网络火力投送平台。</section></li><li><section style="margin-top: 8px;"><strong>持续网络演训环境</strong>（<strong>PCTE</strong>，Persistent Cyber Training Environment）：是<span style="color: rgb(172, 57, 255);"><strong>演训平台</strong></span>，旨在为网络空间作战部队提供持续的网络演训、评估、任务演练；</section></li><li><section style="margin-top: 8px;"><strong>传感器</strong>：用于传递情报、监视和侦察数据，支持网络<strong>防御</strong>和推动<strong>作战</strong>决策。由于传感器常常被忽视，笔者专门用一小节（详见第4.4节）来讨论它。<br/></section></li><li><section style="margin-top: 8px;"><strong>网络工具</strong>：是<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">用于保卫己方网络和攻击敌方系统的各种网络工具。</span></section></li></ol><section style="margin-top: 8px;">下图中关于各个支柱的能力分解，有助于理解<strong>六大支柱</strong>的基本功能：<br/></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.39084065244667504" data-w="1594" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=363a3f3c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNRuqm5GNRrWhOIMOejQQPJmY6Bb0H5qrmdaexrJoPEANo1W94pXQ0MX0PJqxcRQC6750JBiacichibw%2F640%3Fwx_fmt%3Dpng"/></section><p style="margin-bottom: 0px;white-space: normal;text-align: center;">图4-JCWA六大支柱的基本功能</p><p style="margin-top: 8px;">这6大支柱如何统筹运行，以开展网络作战行动呢？笔者专门在4.3节中，用一张2022年8月新发布的<strong>网络作战示意图</strong>（图9；也是本篇微信的封面图）和<strong>流程解读</strong>，来回答这个问题。<br/></p><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">W<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">hy：</span></strong></span></strong></span></strong></strong></strong></strong>为什么要开发JCWA？</span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 8px;"><br/></p><section style="margin-top: 8px;"><strong style="background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;"><strong style="white-space: normal;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 34px;background-color: rgb(255, 255, 255);">3.1 </span></strong>JCWA的根因是网络司令部要独立</span></strong></span></strong></span></strong></strong></strong></strong></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong>官方的说法是：网络司令部</strong>一直希望<strong>摆脱各个军种独立开发各自网络战工具</strong>的情况，希望创建一个更具<strong>联合性</strong>的架构，使得各个军种都可以为整个<strong>网络任务部队</strong>开发工具和能力。于是，网络司令部在<strong>2018年</strong>创建联合网络作战架构（JCWA）。</section><section style="margin-top: 8px;">但笔者认为：从<strong>根因分析</strong>的角度来看，开发JCWA的根本原因是网络司令部要真正地独立。绝大部分人不会意识到这一点。<strong style="color: rgb(34, 34, 34);white-space: normal;background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"></strong></section><section style="margin-top: 8px;">了解美国国防部<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">“双帽体制<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">”的人都清楚，</span></span><strong>网络司令部</strong>是从<strong>NSA</strong>（国家安全局）拆分出来的，而且网络司令部和NSA一直拥有<strong>同一个最高领导人</strong>（这被称为<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">“双帽体制”</span>）。<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br/></span></section><section style="margin-top: 8px;">为了防止2009年新成立的<strong style="white-space: normal;">网络司令部的夭折</strong>，也为了<strong style="white-space: normal;">防止NSA做甩手掌柜</strong>，<strong>2017年《国防授权法案<strong style="white-space: normal;">》</strong></strong>中规定了一项<strong>硬性要</strong><strong>求</strong>：“在分裂之前，参谋长联席会议主席和国防部长必须证明，<strong>如果分裂，网络司令部和NSA的能力都不会降低</strong>。” 也就是说，如果不能证明这一点，网络司令部和NSA就只能维持双帽体系，而不能彻底分离。</section><section style="margin-top: 8px;">笔者认为：网络司令部和NSA的彻底分离必须包含以下三个方面：</section><ol class="list-paddingleft-1" style="list-style-type: lower-alpha;"><li><section style="margin-top: 8px;"><strong>人员和员工的分离</strong>：这一步是<strong>完成时</strong>，即由6千多人组成的133个网络任务部队；</section></li><li><section style="margin-top: 8px;"><strong>基础设施和工具的分离</strong>：这一步是<strong>进行时</strong>，将在下面小节专门解释；</section></li><li><section style="margin-top: 8px;"><strong>领导人的分离</strong>：这一步是<strong>将来时</strong>，也是彻底分离的标志，网络司令部和NSA将不再共用同一领导人。</section></li></ol><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><strong><strong style="white-space: normal;background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;"><strong><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">3.2 </span></strong></span></strong></span></strong></span></strong></strong></strong></strong>为什么</strong><strong style="color: rgb(34, 34, 34);white-space: normal;background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;"><strong style="white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">情报工具和作战工具必须分开</span></strong></span></strong></span></strong></strong></strong></strong></span></strong></span></strong></span></strong></strong></strong></strong></section><section style="margin-top: 8px;">由于作战需要情报支撑这一天然需求，网络司令部与NSA的合作关系将永远保持下去。</section><section style="margin-top: 8px;">但是，两者毕竟扮演<strong>不同的角色</strong>：NSA是一个<strong>情报</strong>组织，执行情报任务；网络司令部是一个<strong>作战</strong>组织，执行作战任务。</section><section style="margin-top: 8px;">所以，从长远来看，正确的答案是将两者分开。这几乎是不可避免的。</section><section style="margin-top: 8px;">正是因为网络司令部具有与NSA不同的任务集，当然就需要单独的基础设施、工具、培训才能独立运作。想想看，旨在延迟、降级、破坏等等的<strong style="white-space: normal;">作战工具</strong>，与旨在驻留和提取信息的<strong>情报工具</strong>，确实是很不相同的。而两者主要重叠的部分在于<strong>网络</strong><strong>渗透</strong>。<br/></section><section style="margin-top: 8px;">从另一方面看，如果网络司令部和NSA共享同一套基础设施和工具集，将对情报工作带来巨大的<strong>潜在风险</strong>：因为作战行动通常执行破坏目标网络的<strong>嘹亮、进攻性</strong>军事行动，并不会过多考虑网络通道的<strong>隐蔽性</strong>。那么，这些嘹亮的攻击行动就可能会导致承载它的网络通道被对手追溯，从而将对手带回 NSA服务器，并获悉NSA的情报能力。这就对NSA的情报工作造成了破坏它。</section><section style="margin-top: 8px;">说得简单点：网络司令部的思考方式是“<strong>我正在打仗，会不会被抓并不重要</strong>！”而NSA的思考方式是“<strong>我在搞间谍活动，绝不想被抓住</strong>！” 让者两拨人使用同一套基础设施，一定会造成互相伤害的。</section><section style="margin-top: 8px;">想想看，如果你搞情报活动的工具上有<strong>作战组织的签名</strong>，那么你的情报活动就很有可能被误会为<strong>战争行动</strong>，从而<strong>违反国际法</strong>。但事实上，这本来只是一项微不足道的情报监视活动。</section><section style="margin-top: 8px;">也正是因为上述原因，情报工具和作战工具必须分开，情报组织和作战组织必须分离。</section><section style="margin-top: 8px;"><br/></section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;"><strong><strong style="white-space: normal;background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;"><strong><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">3.3 </span></strong></span></strong></span></strong></span></strong></strong></strong></strong>JCWA成为</strong><strong style="color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">作战工具的天选之子</span></strong></span></strong></span></strong></strong></strong></strong></section><section style="margin-top: 8px;">在很长一段时间里，网络司令部都使用着NSA的各种工具集，包括斯诺登泄露的那些。但那是<strong>过去时</strong>。</section><section style="margin-bottom: 0px;white-space: normal;margin-top: 8px;">网络战士为了成功执行网络作战任务，需要适合的平台、界面、工具集、基础设施，就像更传统物理领域中的战士一样。独立的网络司令部必然需要自己的基础设施，来执行自己的作战任务。</section><section style="margin-top: 8px;">国防部的多数高层领导认为：除非网络司令部拥有一个<strong>单独平台</strong>来独立开展作战任务，否则就不主张将网络司令部与NSA分开。</section><section style="margin-top: 8px;">这个单独平台的历史使命最终落到JCWA的身上。当然，它在早期也有别的名字，比如<strong>军事网络作战平台（MCOP）</strong>。<br/></section><section style="margin-top: 8px;">所以，笔者才认为：<strong style="white-space: normal;">JCWA是网络</strong><strong style="white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="font-family: PingFangSC-light;text-align: center;">作战平台的天选之子</span></strong></span></strong></span></strong></strong></strong></strong>。</section><section style="margin-top: 8px;">所以，JCWA不仅从网络司令部<strong>独立</strong>的角度来看是必不可少的，而且对于行使网络作战职责的<strong>指挥部</strong>来说也是必不可少的。</section><section style="margin-bottom: 0px;margin-top: 8px;"><br/></section><p class="js_pay_preview_filter"><mp-pay-preview-filter></mp-pay-preview-filter></p>



<p><a href="2247494981">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=13d24c47&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494981%26idx%3D1%26sn%3D4e6ef7993457cd573c65c36c5d5f7462%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 27 Nov 2022 15:29:00 +0800</pubDate>
    </item>
    <item>
      <title>网络安全的三大支柱和攻击向量</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494915&amp;idx=1&amp;sn=9a185bb4f19813af6182a95802e90d40</link>
      <description>身份高于账户，权限细于身份</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学 &amp;amp; 启承</span> <span>2022-09-11 06:59</span> <span style="display: inline-block;">北京</span>
</p>

<p>身份高于账户，权限细于身份</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0e0ad4ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTdg1ABqY5JUnVDPibicIkzJu3ZR9N8zoic8GcAXRyPrv8Yicvl3c726703w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>50</strong><strong>00</strong></span>字  <span style="color:#000000;"><strong>10</strong></span>图表  阅读约<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><strong>BeyondTrust</strong>公司（<strong>连续4年Gartner特权访问管理象限之领导者</strong>）的首席技术官和首席信息安全官Morey Haber（莫雷·哈伯），与人合著，一口气写了三本书：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;margin-bottom: 0px;margin-top: 0px;"><span style="text-align: center;">《<strong>身份</strong>攻击向量》：从<strong>身份</strong>角度出发，考察攻击向量，设计</span><span style="text-align: center;color: rgb(61, 167, 66);"><strong>IAM</strong></span><span style="text-align: center;color: rgb(0, 0, 0);">(身份与访问管理)</span><span style="text-align: center;">方案。</span></p></li><li><p style="letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;margin-bottom: 0px;margin-top: 0px;"><span style="text-align: center;">《<strong>特权</strong>攻击向量》：从<strong>权限</strong>角度出发，考察攻击向量，设计</span><span style="text-align: center;color: rgb(61, 167, 66);"><strong>PAM</strong><span style="color: rgb(0, 0, 0);font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">(特权访问管理)</span></span><span style="text-align: center;">方案。</span></p></li><li><p style="letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;margin-bottom: 0px;margin-top: 0px;"><span style="text-align: center;">《<strong>资产</strong>攻击向量》：从<strong>资产</strong>角度出发，<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">考察攻击向量，设计</span></span><span style="text-align: center;color: rgb(61, 167, 66);"><strong>漏洞</strong><strong>管理</strong></span><span style="text-align: center;">方案。</span></p></li></ul><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">有趣的是，作者认为：这三本书正好构建了网络安全的</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);"><strong>三大支柱</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">：<strong>1）身份；2）权限；3）资产</strong>。而只有基于稳固的<strong>三角架</strong>结构，才能构建稳健的安全基础。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">最值得提醒的是：<strong>三大支柱的</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);"><strong>集成/整合</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"><strong>至关重要</strong>。一个好的安全解决方案一定要有利于三大支柱的集成。反之，如果一个安全方案没有跨这三个支柱来运行，也没有促进三大支柱的互操作性和数据集成，那么它就是一个孤岛解决方案。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">对于如此系统阐述其<strong>安全框架</strong>和<strong>具体方案</strong>的系列书籍，笔者自然不愿错过。在纵览近千页的英文版后，希望将其推荐给大家。<br/></span></p><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">目前，《身份攻击向量》<strong>中文版</strong>已经于2022年8月面市，在此感谢译者赠书！据悉，另外两本也在翻译过程之中。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">本文试图以<strong>世界顶级IAM和PAM专家</strong>的视角，反映<strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">身份和权限</span></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">的攻击向量和防御之道。</span></span></p><p style="text-align: left;margin-top: 10px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"><span style="outline: 0px;max-width: 100%;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">看见是王道</strong></span><strong style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">！孤岛很糟糕</strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">。你是在创造“看见”，还是在创造“孤岛”？你能<strong>同时看见<strong style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: center;white-space: normal;">漏洞、</strong></strong><strong>身份、权限</strong>吗？</span></span></span></p></section></section></section></section></section><section>关键词：<strong>IAM</strong><span style="font-size: 17px;">（身份和访问管理）；<strong style="font-size: 20px;text-align: center;"><strong style="text-align: center;white-space: normal;font-size: 20px;"></strong></strong></span><strong>PAM</strong><span style="font-size: 17px;">（特权访问管理）；</span><strong style="font-size: 20px;text-align: center;"></strong></section><section style="margin-top: 15px;text-align: center;margin-bottom: 15px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><p style="margin-bottom: 0px;margin-top: 0px;">1.网络安全的<strong>三大支柱</strong></p><p style="margin-bottom: 0px;margin-top: 0px;">2.横向移动的<strong>攻击向量</strong></p><p style="margin-bottom: 0px;margin-top: 0px;">3.网络杀伤链中的<strong>身份攻击向量</strong></p><p style="margin-bottom: 0px;margin-top: 0px;">4.从<strong>传统4A</strong>到<strong>现代5A</strong><br/></p><p style="margin-bottom: 0px;text-indent: 2em;">1）IAM(身份访问管理)的5个A</p><p style="margin-bottom: 0px;text-indent: 2em;">2）为何少了<strong>账户</strong>(Account)？</p><p style="margin-bottom: 0px;text-indent: 2em;">3）为何多了<strong>管理</strong>(Administration)？</p><p style="margin-bottom: 0px;text-indent: 2em;">4）为何多了<strong>分析</strong>(Analytics)？</p><p style="margin-bottom: 0px;margin-top: 0px;">5.从<strong>IAM</strong>(身份访问管理)到<strong>PAM</strong>(特权访问管理)</p><p style="margin-bottom: 0px;margin-top: 0px;">6.洞察和见解</p><p style="margin-top: 0px;margin-bottom: 24px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;margin-bottom: 0px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-left: 0px;margin-right: 0px;margin-bottom: 0px;"><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">网络安全的三大支柱</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 24px;"><span style="font-size: 17px;text-align: center;">作者认为：在宏观层面上，如果对所有安全解决方案进行分组，就会发现每个方案都属于三个逻辑分组之一。这三个逻辑分组构成了网络安全的三大支柱。如下图所示：</span></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.6025299600532623" data-w="1502" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ce7c7f94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTj4NejwFqYxnNyb374yuIubC1ZeXBCAjVfcSkkBRZOibsb4z7M5E7Rpg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">图1-网络安全的三大支柱</span> </span></section><p style="margin-bottom: 0px;margin-top: 24px;"><strong>三大支柱：</strong></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p><strong>身份(Identity)</strong>：保护用户的<strong>身份、帐户、凭证</strong>，免受不当的访问；</p></li><li><p><strong>权限(Privilege)</strong>：对<strong>权限和特权</strong>的保护，以及对身份或帐户的<strong>访问控制</strong>；</p></li><li><p><strong>资产(Asset)</strong>：对一个身份所使用（直接使用或作为服务使用）的<strong>资源</strong>的保护；</p></li></ol><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">一个好的安全解决方案应该同时涵盖所有三个支柱，而这<strong>三大支柱的集成/整合至关重要</strong>。所以，<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">一个好的安全解决方案一定要有利于三大支柱的集成/整合。</span></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">如果一个安全解决方案只能<strong>孤立运行</strong>，无法与其它方案兼容，也无法使三个支柱互通，就无法有效应对现代威胁：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">比如<strong>孤立的</strong></span><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>杀毒软件</strong></span><span style="font-size: 17px;"><strong>方案</strong>：虽然能够报告资产的感染情况，却无法判断恶意软件使用什么<strong>身份</strong>（账户或用户）或<strong>权限</strong>来入侵目标资产。因为它无法共享和获取用户的身份信息和身份的上下文。</span></section></li><li><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">再比如<strong>孤立的</strong></span><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>漏洞管理</strong></span><span style="font-size: 17px;"><strong>方案</strong>：虽然能够扫描到资产的漏洞信息，却无法发现可访问该资产的<strong>账户和用户组</strong>信息，也就无法更好地帮助确定补丁的优先级，也无法帮助管理好身份攻击向量。<br/></span></section></li></ul><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">话再说得狠一点：<strong>如果一个安全厂商没有跨这三个支柱来运行，也没有促进三大支柱的互操作性和数据交换的集成/整合策略</strong>，那么它确实就是一个</span><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong>单点/孤岛解决方案</strong></span><span style="font-size: 17px;">。请慎用这样的方案。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">为何是3大支柱，而不是4或5根支柱？作者解释说：因为3条腿的凳子不会晃！</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">作者为三大支柱分别写了一本书：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">《<strong>身份</strong>攻击向量》：中文版<strong>已出版</strong>。<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">本文主要引自该书。该书更多地从<strong>身份</strong>角度出发，考察攻击向量，设计</span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(61, 167, 66);"><strong>IAM</strong></span><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">方案。</span></section></li><li><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">《<strong>特权</strong>攻击向量》：中文版尚在编写过程中，<strong>待出版</strong>。<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">该书更多地从<strong>权限</strong>角度出发，<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">考察攻击向量，设计</span></span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(61, 167, 66);"><strong>PAM</strong></span><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">方案。</span></section></li><li><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">《<strong>资产</strong>攻击向量》：<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">中文版尚<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">在编写过程中，</span></span><strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">待出版</span></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">。该书主要讲述<strong>资产</strong></span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(61, 167, 66);"><strong>漏洞</strong></span><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"><strong>管理</strong>。其重要性在于：漏洞管理是安全的基础。<strong>当资产本身可被<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;white-space: normal;">漏洞</strong>利用时，身份也难以得到保护</strong>。<br/></span></section></li></ol><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">横向移动的</strong></span></strong></span></strong></strong></strong></strong>攻击向量</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">攻击向量总体上可以分为两类：1）<strong>资产</strong>攻击向量；2）<strong>权限</strong>攻击向量。这两类正好对应于作者的两本书：《<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">资产</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">攻击向量</span>》和《<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">特权</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">攻击向量</span>》。</span></section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><p style="margin-top: 15px;"><strong>资产攻击向量/方法</strong>：一般通过<strong>漏洞和配置缺陷</strong>来实现。防御方法是漏洞管理、补丁管理、配置管理等传统的网络安全最佳实践。在这个方面，每个组织都应该做好，但在现实中并非如此。<br/></p></li><li><section style="margin-top: 15px;"><strong>权限攻击向量/方法</strong>：通常采取某种形式的<strong>特权远程访问</strong>，所用技术包括口令猜测、字典攻击、暴力破解、Hash传递、口令重置、默认凭据、后门凭证、共享凭据等。防御方法是<strong>零信任模型</strong>和<strong>即时(JIT)权限访问管理</strong>。</section></li></ul><section style="margin-top: 15px;margin-bottom: 24px;white-space: normal;">值得特别说明的是：(狭义)零信任、即时身份、特权访问管理这样的现代安全模型，主要用于缓解<strong style="white-space: normal;">权限攻击向量</strong>，并不能缓解<strong>资产攻击向量</strong>。</section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;"></span><strong><span style="font-size: 17px;">横向移动</span></strong><span style="font-size: 17px;">是勒索软件、机器人（Bot）、蠕虫和其他恶意软件等现代威胁的主要攻击手段。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;"></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;"><strong style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;text-align: left;white-space: normal;">横向移动</strong>是指从一种资源转向另一种资源并在这些资源之间持续跳转的能力。所谓“</span><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong>资源</strong></span><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">”，不仅指<strong>资产</strong>（如计算机、操作系统、应用程序、容器、虚拟机等），还包括账户和身份（如下表第一列所示<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">）</span>。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">以<strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">横向移动攻击</span></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">为例，两类攻击向量的示例如下表所示：</span><br/></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.6125198098256736" data-w="1262" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cfe98c10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHT2PAYkCs3qc4381OErVjNUjHDiaOJIUkJOjk5OKPic1GibcdAXZH3HSqyA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-size: 17px;">表2-<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">横向移动技术中的攻击向量</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"></span></span></section><p style="margin-bottom: 0px;margin-top: 0px;"><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">上面只提到了两个支柱的攻击向量，第三个支柱（身份）的攻击向量呢？</span><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">我们将在下一小节专门呈现。</span><br/></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 24px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">网络杀伤链中的身份攻击向量</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">以业界熟知的网络杀伤链为例，来看看身份攻击向量的表现方式。我们按照<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">杀伤链的四个阶段来分别反映（身份攻击向量以</span></span><strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(0, 82, 255);">蓝色字体</span></strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">标记）：<br/></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.5184940554821664" data-w="1514" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=535f7f5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTP5mrXj8CYicdE8qPanM8uVK085ChDPcFEJnuuTIN7WrCPpZiaXL98xCQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;">图3-侦察阶段的身份攻击向量</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.5171730515191546" data-w="1514" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a4552d2e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTYfXwKSCPMX8vYo86Xd171jcVib85FvWNyDe9vlfyrGGx0qCdgeL9xbA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-size: 17px;">图4-入侵阶段的身份攻击向量</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.5184940554821664" data-w="1514" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=92f86595&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTX0AEGr9kabRWqDPicyuibatwGQxd6yYibl99UianRu3hqRtw1GtsHibuWSg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;">图5-利用阶段的身份攻击向量</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"><img class="rich_pages wxw-img" data-ratio="0.5184940554821664" data-w="1514" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5386dca0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTSRyVckgjS2yFvhNCdUyYoSH5Ax7rKbIBYUF8TYHf2uvylw0PZ8WBJw%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);font-size: 17px;">图6-渗出阶段的身份攻击向量</span></section><section style="margin-top: 15px;margin-bottom: 24px;text-align: left;">从上述攻击链的四个阶段来看，身份攻击的重点在于其中的两个阶段：入侵阶段和利用阶段。在这两个阶段中，身份攻击的主要目标是两个：权限提升和横向移动。</section><section style="margin-top: 15px;margin-bottom: 24px;text-align: left;">所以，可以得出的结论是：身份攻击向量的本质是构建<span style="color: rgb(0, 82, 255);"><strong>权限攻击链</strong></span>，以实现<span style="text-align: left;">权限提升和横向移动。如下图中的<strong>蓝色虚线小圈</strong>所示：</span></section><section style="margin-top: 15px;margin-bottom: 24px;text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.7285298398835517" style="text-align: justify;" data-type="png" data-w="1374" src="https://wechat2rss.xlab.app/img-proxy/?k=30878a17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMyy4mo8kTZgsJjRnNccIDMicNmtbrPdIBbxKdOLrR2oQicfPQZq8l7icWWwcpTEGsjzHc5sFsPh9xAw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 24px;text-align: center;">图7-权限攻击链</section><section style="margin-top: 15px;margin-bottom: 24px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">从传统4A到现代5A</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-bottom: 24px;margin-top: 24px;"><strong style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;text-align: left;"><span style="font-size: 17px;">1）IAM(身份访问管理)的5个A</span></strong><br/></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.5409511228533685" style="font-size: 17px;" data-type="png" data-w="1514" src="https://wechat2rss.xlab.app/img-proxy/?k=00fe511c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTrXF3hHVygicsCpW638ibX5jia8WicwQyo2H6micZEwRJwagwicmB1DGo9vPQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-size: 17px;">图8-身份管理的五个A<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"></span></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">IAM的<strong>新5A</strong>是指认证(Authentication)、授权(Authorization)、</span><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>管理</strong></span><span style="font-size: 17px;">(Administration)、审计<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Audit<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)</span>、</span><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>分析</strong></span><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Analytics<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)</span>。<br/></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">而<strong>传统4A</strong>是指认证<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Authentication<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)</span>、授权<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Authorization<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)</span>、</span><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">账户</strong></strong></span><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Account<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)</span>、审计<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(</span>Audit<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">)。</span></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><strong><span style="font-size: 17px;">新5A和老4A的共性</span></strong><span style="font-size: 17px;">是：认证、授权、审计。审计就不说了。书中对<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">认证、<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">授权给了如下简明公式</span>：</span></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 15px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-bottom: 0px;"><strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">认证</span></strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">=登录名+密钥（口令）；</span></p></li><li><p style="margin-top: 15px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-bottom: 0px;"><strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">授权</span></strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">=权限(privilege)+认证；</span></p></li></ul><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">新5A和老4A的</span>区别</span></strong><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">是：少了<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">账户</strong></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Account)，但多了<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);">管理</strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Administration)和<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);">分析</strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Analytics)。</span></span></span></span>这块涉及到新5A和老4A的</span><strong><span style="font-size: 17px;">理念</span></strong><span style="font-size: 17px;">问题，故值得解释一下。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><strong><span style="font-size: 17px;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">2）为何少了<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);"><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">账户</strong></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Account)？</span></span></strong></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;">笔者认为：这与该书作者<strong>强调“身份<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">”而弱化“账户”</span></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">有关。</span><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">这里就涉及<strong>身份与账户和用户的区别</strong>：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-bottom: 0px;"><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">账户</strong>是<strong>身份</strong>的电子表示；<br/></section></li><li><section style="margin-top: 15px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;margin-bottom: 0px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">一个<strong>身份</strong>可以对应到多个<strong>账户</strong>；</span></section></li><li><section style="margin-top: 15px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;margin-bottom: 0px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">一个<strong>身份</strong>只能对应到一个<strong>用户</strong>；</span></section></li></ul><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">从身份安全的角度看，<strong>身份比账户更重要</strong>。但身份只能通过账户来发挥作用，<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">账户是身份的表现形式。</span>而<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">账户</span>能否真正发挥身份的价值，取决于账户能否能被映射到身份上。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">所以，<strong>账户与身份的</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(61, 167, 66);"><strong>关联</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);"><strong>至关重要</strong>。无法关联到身份的账户，都是身份的攻击向量。比如企业中常见的“<strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">孤儿帐户</span></strong>”，即那些没有关联到已知用户的帐户。还有应用程序用来访问数据库的<strong>共享服务账户</strong>，如果无法关联到真实的用户身份，就没法知道究竟是谁访问了你的数据（参见</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494874&amp;idx=1&amp;sn=db320cee01958cdcd7ef1cec394c32f4&amp;chksm=97fa31bca08db8aaee282392bf938c53b5abb6da7deb881a0e2c33b6bb1199141935e632f241&amp;scene=21#wechat_redirect" textvalue="谁动了你的数据？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);text-decoration: underline;color: rgb(0, 82, 255);" data-linktype="2"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);text-decoration: underline;color: rgb(0, 82, 255);">谁动了你的数据？</span></a><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(0, 82, 255);">》</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">）。而现代身份治理的核心目标之一正是将账户与真实用户（身份）建立关联，尽量消除孤儿账户的存在。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">所以，在传统4A中，尽管已有账户体系，但很多时候却无法映射到身份。这就是</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(61, 167, 66);"><strong>传统4A只是账户安全</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">，而</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(61, 167, 66);"><strong>现代5A才是身份安全</strong></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">的原因。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">这里甚至涉及到类似哲学层面的问题：<strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">账户可以赋予一切网络主体</span></strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">，而</span><strong>身份只能赋予</strong><strong>人类</strong><strong>或软件</strong><strong>机器人</strong>。也就是说，一个网络主体（应用程序、网络设备等）是否被赋予身份，要看它是否模仿一个人。想要模仿人的（比如<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">快递</strong><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;">机器人</strong>）才需要身份，否则只需要赋予账户即可。也就是说，通常的网络设备和应用程序，只需要分配账户即可。</span>过度分配身份，将会把问题复杂化，也会导致更大的攻击向量（因为<strong>身份攻击向量大于账户攻击向量</strong>）。</section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;">我们曾经设想，在即将来临的万物互联时代，要对联网的万事万物（物联网设备）都分配数字身份。看完这本书时，你必然产生大大的问号。因为它不像我们之前想的那么简单。</section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><strong><span style="font-size: 17px;">3）为何多了<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);">管理</strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Administration)</span>？</span></strong></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">此处的管理是指对身份验证、授权、审计的任何变化进行配置管理和治理控制。</span><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">在IAM领域发展了<strong>25年</strong>之后，我们回头想一想：有多少东西发生了变化，又有多少东西没有变化。就会发现：</span><strong><span style="font-size: 17px;">认证</span></strong><span style="font-size: 17px;">(Authentication)</span><span style="font-size: 17px;">和</span><strong><span style="font-size: 17px;">授权</span></strong><span style="font-size: 17px;">(Authorization)技术</span><span style="font-size: 17px;">发现了太大变</span><span style="font-size: 17px;">化</span><span style="font-size: 17px;">；</span><span style="font-size: 17px;">而</span><strong><span style="font-size: 17px;">管理</span></strong><span style="font-size: 17px;">(Administration)</span><span style="font-size: 17px;">一直是比较稳定</span><span style="font-size: 17px;">的需求（也一直没有做好）。所以，才要<strong>把管理从认证和授权中分离出来</strong>，构成单独的一个A。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">也许你会问起<strong>身份治理</strong>（Identity Governance），而<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">身份治理恰恰涵盖了</span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(0, 0, 0);"><strong>管理</strong>(Administration)、<strong>审计</strong>(Audit)、<strong>分析</strong>(Analytics)这<strong>三个A</strong>。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 15px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-bottom: 24px;"><strong><span style="font-size: 17px;">4）为何多了<strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);">分析</strong><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">(Analytics)</span>？</span></strong></p><p><strong>分析</strong>是指通过持续收集和处理与身份相关的配置、分配、使用数据，获得<strong>运营和安全洞察</strong>。<br/></p><p><strong>高级身份分析</strong>支持更明智、更具预测性的治理方法。通过使用机器学习(ML)和人工智能(AI)技术，身份分析工具可以提供重要的<strong>对等组分析</strong>信息，有助于扩展身份审核和管理功能，并使它们更具动态性和响应性。</p><p><strong>传统4A缺少分析</strong>。随着机器学习(ML)和人工智能(AI)的进步，现在可以发现和处理大量的运营数据，以揭示隐秘的洞察和可操作的指示，远远超越了<strong>传统的基于规则的引擎</strong>所能实现的能力。</p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 24px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">从IAM到PAM</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 40px;margin-bottom: 24px;"><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>领域</strong></span><span style="font-size: 17px;"><strong>的差异</strong>。<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">IAM（身份与访问管理）更加侧重于</span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(61, 167, 66);"><strong>身份</strong></span><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">；PAM（</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">特权访问管理</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">）更加侧重于</span></span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);font-size: 17px;color: rgb(61, 167, 66);"><strong>权限</strong></span><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">。两者分别应对了<strong>两大支柱</strong>（即身份支柱和权限支柱）的安全需求。</span></span></p><section style="white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-bottom: 24px;margin-top: 24px;"><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong>功能</strong></span><span style="font-size: 17px;"><strong>的差异</strong>。下图展示了IAM和PAM的功能组成：</span></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 40px;"><span style="font-size: 17px;"></span></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 40px;"><span style="font-size: 17px;"></span></section><section style="margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;margin-top: 40px;"><strong style="text-align: center;font-size: 17px;"><img class="rich_pages wxw-img" data-ratio="0.6020782396088019" data-w="1636" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3d00be72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHT9yoMIRAAFIZ09N3A4dlQKQj45wpmn7W66ic1MYp7oUJuIwiayn3A78BQ%2F640%3Fwx_fmt%3Dpng"/></strong></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: center;line-height: 1.5em;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">图9-IAM和PAM的组件</span><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);"></span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="color: rgb(61, 167, 66);"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">用户</strong></span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">的差异</strong>。<strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">特权</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">是比普通权限更高的权限。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">对用户的最基本分类是两种：</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">标准用户</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">（具有普通权限）和</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">管理员</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">（具有</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">特权</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">，还进一步分为</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">本地</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">管理员和</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">域</strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">管理员）。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;">通常，也会增加</span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">来宾用户</span></strong><span style="text-align: justify;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">（<span style="letter-spacing: 0.544px;">低于标准用户的权限</span>）。</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: justify;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"></span></span></section><p>关于用户的更加精细的划分。我们以具有制造环境的组织为例，IAM和PAM的用户范围如下图所示：<br/></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.666904422253923" data-w="1402" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=77e70706&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNkbUDicic0PHA4U55gDr2ZHTH0znmDmxPVkibhXB9TbLaWuoYk70I1hEz3GvpF2icXibAt46xePJD0xTQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: center;line-height: 1.5em;">图10-IAM和PAM的范畴对比<br/></section><p style="margin-bottom: 24px;white-space: normal;"><span style="color: rgb(61, 167, 66);"><strong>资源</strong></span><strong>的差异</strong>。<strong>权限的视角</strong>一方面是在<strong>宏观</strong><span style="color: rgb(172, 57, 255);"><strong>用户</strong></span><strong>级别</strong>上（这是IAM侧重的），另一方面是在<strong>微观</strong><span style="color: rgb(172, 57, 255);"><strong>资源</strong></span><strong>级别</strong>上（这是PAM侧重的）。从资源层面看，将权限仅仅视作应用程序的一部分，是短视的。<span style="color: rgb(172, 57, 255);"><strong>权限还必须嵌入到资源的每个层次中</strong></span><strong>，即嵌入到操作系统、文件系统、应用程序、数据库、虚拟机管理程序、云管理平台，甚至通过分段嵌入网络中</strong>，才能应对高级别的权限攻击。</p><p style="margin-bottom: 24px;white-space: normal;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;color: rgb(61, 167, 66);"><strong><strong><strong style="color: rgb(61, 167, 66);font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;white-space: normal;background-color: rgb(255, 255, 255);">可见性</strong></strong></strong></span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;"><strong>的差异</strong>。</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">IAM可以回答“</span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">谁有权访问什么</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">？</span><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">”但是，为了实现完全的用户可见性，PAM解决了剩下的问题:“</span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">这种访问合适吗</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">？</span><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">”以及“</span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">这种访问是否被恰当地使用</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">?”也就是说，PAM可以对特权帐户的访问和使用提供</span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">更多的可见性</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">和</span><strong style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">更深入的审计</strong><span style="background-color: white;font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;">。</span></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;">很多时候，IAM会将用户添加到系统或应用程序<strong>组</strong>中，但不会提供有关该组成员具备的访问权限的详细信息，也不会提供对特权会话期间收集的详细会话日志或键盘记录的访问能力。而PAM可以扩展这些能力。因此，<strong>PAM扩展了IAM解决方案的可见性</strong>。</section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;">特别说明：在同一作者的另一篇书籍<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: center;background-color: rgb(255, 255, 255);">《特权攻击向量》中，系统阐述了<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">PAM</span>。而《身份攻击向量》的翻译团队也正在对其进行翻译中。期待译本在不久的未来面世。</span><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;text-align: left;line-height: 1.5em;"><strong><br/></strong></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin-bottom: 24px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">洞察和见解</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 24px;margin-bottom: 16px;">在该书的最后一章中，作者给出了身份访问管理（IAM）的关键原则：<br/></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="margin-bottom: 0px;margin-top: 8px;"><strong>思考</strong><span style="color: rgb(172, 57, 255);"><strong>身份</strong></span><strong>而非</strong><span style="color: rgb(172, 57, 255);"><strong>账户</strong></span>。组织中的一个用户通常拥有多个帐户和每个帐户的多项权限。如果企业只将IAM计划的重点放在<strong>帐户级别（而非身份级别）</strong>的管理上，它将永远无法获得正确了解“<strong>谁有权访问什么</strong>”所需的<strong>整体可见性</strong>。理解<strong>身份与其帐户之间</strong>、<strong>帐户与其权限之间</strong>、<strong>权限与其保护的数据/信息之间</strong>的三向关系是关键。只有<strong>围绕身份（而非账户）</strong>来集中相关数据，企业才能形成正确的视图和可见性。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><span style="color: rgb(172, 57, 255);"><strong>看见是王道</strong></span><strong>！孤岛很糟糕</strong>。伴随着云、物、移、大的趋势，<strong>集中化的</strong><span style="color: rgb(0, 0, 0);"><strong>单点可见性</strong></span>成为组织安全性之关键。唯有如此，才能确保在企业范围内看见其<strong>身份</strong><strong>和访问数据</strong>。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><strong>全生命周期的身份治理是必需的</strong>。通过在身份的整个生命周期中嵌入策略和控制，组织可以实现增强的自动化、持续的合规性、降低的安全风险。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><strong>将IAM与PAM集成部署</strong>。PAM是对IAM方案的补充，增加了对&#34;特权&#34;帐户的控制和审计层。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><strong>采用预测性方法</strong>。积极应用<strong>机器学习</strong>和<strong>人工智能</strong>技术，以实现更加智能、更加明智的访问决策。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><strong>实现最小权限</strong>。</p></li><li><p style="margin-bottom: 0px;margin-top: 8px;"><span style="color: rgb(172, 57, 255);"><strong>用户体验至上</strong></span>！身份治理和权限管理技术必须有助于提供更好的用户体验，如果不想被业务人员否定其安全价值。</p></li></ol><section style="margin-top: 0px;"><br/></section><section style="margin-top: 0px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></section>



<p><a href="2247494915">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dc1e01ea&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494915%26idx%3D1%26sn%3D9a185bb4f19813af6182a95802e90d40%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 11 Sep 2022 06:59:00 +0800</pubDate>
    </item>
    <item>
      <title>谁动了你的数据？</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494874&amp;idx=1&amp;sn=db320cee01958cdcd7ef1cec394c32f4</link>
      <description>你以为你以为的，就是你以为的吗？</description>
      <content:encoded><![CDATA[<p>
原创 <span>一帆 &amp;amp; 柯学</span> <span>2022-09-04 06:06</span> <span style="display: inline-block;">北京</span>
</p>

<p>你以为你以为的，就是你以为的吗？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=745346a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPPiaAJRvmhWWmicrFZ2w609OMErADJQyiayCVicgXCbTGabdFQlfTgw5iblhtib9EYHeic8q7KwjkMW0jOWQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>40</strong><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="max-width: 100%;margin-bottom: 0px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">“谁访问了你的数据？” 这看似一个简单的问题，却很难回答：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">首先，</span><span style="background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;color: rgb(0, 82, 255);"><strong>你以为</strong></span><strong><span style="background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">数据库日志</span></strong><span style="background-color: rgb(255, 255, 255);color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">记录了身份，但数据库日志常常是被禁用的；</span><br/></section></li><li><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">然后，</span><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 82, 255);"><strong>你以为</strong></span><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);"><strong>应用程序日志</strong></span><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">记录了身份，但</span><span style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">其实没有</span><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">；</span></span></section></li><li><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">于是，</span><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 82, 255);"><strong>你以为</strong></span><span style="background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">强行<strong>启用数据库日志</strong><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">就可以解决问题，但并没有；</span></span></section></li><li><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">接着，</span><span style="font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 82, 255);display: inline !important;"><strong>你以为</strong></span><span style="font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 0, 0);display: inline !important;"><strong>应用程序</strong></span><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">可以把身份带给数据，但其实不行；</span></section></li><li><section style="white-space: normal;text-align: left;margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">终于，</span><span style="font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(0, 82, 255);display: inline !important;"><strong>你以为</strong></span><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">这样就没辙了，但聊暗花明又一村……</span></section></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">上述问题本质上是<strong>数据访问的</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(172, 57, 255);"><strong>身份归因</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">我们知道，对于<strong>应用程序的访问</strong>而言，身份归因是比较容易的，通常由<strong style="margin: 0px;padding: 0px;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">单点登录(SSO)</strong>即可解决；那对于<strong>数据的访问</strong>，身份归因为何就如此困难呢？<strong style="margin: 0px;padding: 0px;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">区别就在于：“<strong>谁访问了你的</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(172, 57, 255);"><strong>应用</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">”</span>并不等同于<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">“</span><strong>谁访问了你的</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(172, 57, 255);"><strong>数据</strong></span><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">”</span>。在应用程序和数据之间，存在一条难以逾越的大河。<br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">所以，将零信任<strong>思想</strong>应用于数据访问时，听起来很简单；但将零信任<strong>技术</strong>应用于数据访问时，做起来却很困难。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">当然，对于正确的事情，即使困难，也该做。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;clear: both;min-height: 1em;"><span style="margin: 0px;padding: 0px;background-color: rgb(255, 255, 255);letter-spacing: 0.544px;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">再问一遍：在贵组织的数据访问过程中，真地有<strong>用户身份</strong>吗？</span></section></section></section></section></section></section><p style="text-align: left;margin-bottom: 15px;margin-top: 8px;"><strong style="font-size: 20px;text-align: center;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">关键词：</span></strong><strong style="font-size: 20px;text-align: center;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">SSO（单点登录）；<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: justify;float: none;display: inline !important;">DSP</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;text-align: center;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">（数据安全平台）；身份提供者（IdP<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;text-align: center;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;text-align: center;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;">）</span></strong></span></strong>；</span></strong></span></strong></p><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section style="white-space: normal;margin-bottom: 0px;">1.问题：谁访问了你的数据？</section><p>2.你以为数据库日志是默认启用的</p><p>3.你以为应用程序日志可以办到</p><p>4.你以为强行启用数据库日志就好</p><p>5.既然无解，请向前辈(应用程序)学习<br/></p><p>6.然而，数据并没有SSO(单点登录)</p><p>7.既然没有数据SSO，那就创造一个</p><p>8.答案：具备数据SSO的数据访问平台</p><p><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">问题：谁访问了你的数据？</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></p><section style="margin-top: 8px;">谁访问了你的数据？很容易提问，但很难回答。</section><section style="margin-top: 8px;">当我们在被审计过程中试图证明我们过去的访问行为是正当的时，我们可能会被问到这个问题；当我们处理数据泄露问题时，我们可能会被问到这个问题。<br/></section><section style="margin-top: 8px;">在大多数情况下，我们都以非常被动的方式回答这些数据。因为我们<strong>看不清</strong>也<strong>说不清</strong>这个问题。</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">当被问及这个问题时，你可能会觉得自己被置于聚光灯下，甚至是审讯椅上。<br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">你以为数据库日志是默认启用的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin-top: 8px;">遇到这个问题，我们通常的想法是查看数据库日志，看看是否可以找到答案。但通常<strong>没有数据库日志</strong>，因为<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">据库日志经常被</span>禁用。<br/></section><section style="margin-top: 8px;"><strong>为什么我们经常会关闭数据库日志呢？ </strong></section><section style="margin-top: 8px;"><strong>一是延迟</strong>。通常，<strong>应用程序中的最慢部分就是数据访问</strong>，即连接到数据库并检索数据。而数据库检索数据的最慢部分是从磁盘读取数据。当我们写入日志时，我们需要执行两个磁盘操作，从而增加了应用程序的延迟。因此，出于性能原因，我们可能会选择禁用日志记录。</section><section style="margin-top: 8px;"><strong>二是存储</strong>。我们也可能出于存储原因选择禁用日志。数据库服务器的工作是存储关键业务数据。随着时间的推移，我们可能会存储大量数据，导致我们很久以前选择的磁盘大小现在可能不够了。我们只好先删除一些不需要的东西，首先想到的自然是删除数据库日志。</section><section style="margin-top: 8px;">另一方面，即便数据库日志<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">存在，它们可能太贫乏而无法获得有价值的见解。对此，后文再做解释。</span></section><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">你以为应用程序日志可以办到<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin-top: 8px;">接下来，我们考虑应用程序日志。<br/></section><section style="margin-top: 8px;">任何使用我们数据库的东西，都可能来自我们的应用程序。值得庆幸地是，<strong>我们对应用程序的使用过程有很好的日志记录</strong>。我们可能有非常漂亮的仪表板，向我们展示经过身份验证的用户活动、页面请求、响应HTTP状态代码，以及完成请求所花费的时间。于是，我们希望通过这些日志来回答“谁访问了我们的数据？”这个问题。<br/></section><section style="margin-top: 8px;">但是应用程序日志是否足以回答这个问题？不幸的是，并非如此。因为还<span style="color: rgb(172, 57, 255);"><strong>存在许多不通过应用程序连接到数据库的场景</strong></span>：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="color: rgb(0, 0, 0);"><strong>SRE</strong>（<span style="color: rgb(0, 0, 0);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">站点可靠性工程师</span>，Site Reliability Engineer）：</span>会跳转到客户帐户，以快速修复一些数据错误并让客户恢复正常。</section></li><li><section style="margin-top: 8px;"><strong>DBA</strong><strong>(数据库管理员)</strong>：直接登录数据库，以调整索引或重写慢查询。</section></li><li><section style="margin-top: 8px;"><strong>部署工具</strong>：运行数据库迁移，以部署软件的新版本。</section></li><li><section style="margin-top: 8px;"><strong>批量数据提取工具</strong>：可以帮助新客户加入或帮助老<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">客户</span>离开。</section></li></ul><section style="margin-top: 8px;">这些连接是否通过应用程序？他们可能不是。他们<strong>可能通过</strong><span style="color: rgb(172, 57, 255);"><strong>数据库管理工具</strong></span><strong>直接访问数据库</strong>。</section><section style="margin-top: 8px;">还可以列举多种<strong>合法</strong>的场景，其中正常的数据访问都不是通过我们的应用程序完成的；而对于其它<strong>不合法</strong>的活动，当然很可能也不是通过应用程序来完成的。</section><section style="margin-top: 8px;">使用应用程序日志来回答有关数据库访问的问题，仍是一个<strong>谎言</strong>。因为数据访问不仅仅通过应用程序发生。</section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">你以为强行启用数据库日志就好<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin-top: 8px;">既然没辙，就让我们启用数据库日志吧。<br/></section><section style="margin-top: 8px;">如果我们查看Postgres官方文档，就会发现：<strong>默认情况下日志是禁用的</strong>——正如前文所述。</section><section style="margin-top: 8px;">当然，我们可以<strong>启用日志</strong>，即通过如下配置，<strong>将日志级别从</strong><span style="color: rgb(172, 57, 255);"><strong>无</strong></span><strong>更改为</strong><span style="color: rgb(172, 57, 255);"><strong>全部</strong></span>：</section><section style="margin-top: 8px;">postgres -c <span style="color: rgb(61, 167, 66);">log_statement=all </span>-c <span style="color: rgb(61, 167, 66);">logging_collector=on</span></section><section style="margin-top: 8px;"><span style="white-space: pre-wrap;">启用日志后，再重启数据库。然后，使用<strong>应用程序</strong>和终端工具访问数据库。这时，我们可以看到类似下面的日志信息：</span></section><p style="margin-bottom: 0px;margin-top: 8px;"><span style="font-size: 15px;">2021-02-21 15:35:07 CET [3492-349] postgres@prod LOG:<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">  </span>execute &lt;unnamed&gt;: SELECT id FROM public.task WHERE <span style="color: rgb(61, 167, 66);">id</span> = 7;</span></p><section style="margin-bottom: 0px;margin-top: 0px;"><span style="font-size: 15px;">2021-02-21 15:35:07 CET [3492-350] postgres@prod LOG:  duration: 11.069 ms</span></section><section style="margin-bottom: 0px;margin-top: 0px;"><span style="font-size: 15px;">2021-02-21 15:35:08 CET [3494-223] postgres@prod LOG:  duration: 0.030 ms</span></section><section style="margin-bottom: 0px;margin-top: 0px;"><span style="font-size: 15px;">2021-02-21 15:35:08 CET [3494-224] postgres@prod LOG:  duration: 0.081 ms</span></section><section style="margin-top: 8px;">我们的确可以看到<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">执行的</span>查询操作、查询的日期/时间、消耗的时间，<span style="color: rgb(61, 167, 66);"><strong>但</strong><strong>看不到<strong style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">查询是由</strong>谁执行的</strong></span>。<strong>即便我们想记录用户信息，我们可能只会看到应用程序使用的</strong><span style="color: rgb(61, 167, 66);"><strong>服务帐户</strong></span>。</section><section style="margin-top: 8px;">而即便是由<strong>非应用程序型工具</strong>所运行的查询，也可能仍然使用相同的<strong>服务帐户</strong>。我敢打赌，DBA或SRE用户只是打开了Web应用程序，又从配置文件中提取了凭据，然后登录。</section><section style="margin-top: 8px;"><strong>为何会执着地使用</strong><span style="color: rgb(61, 167, 66);"><strong>服务帐户</strong></span><strong>？因为在数据库中创建个人用户，并使其在员工加入和离开时保持同步，真是太困难了</strong>——所以没法这么做。于是，大家都使用相同的服务帐户。</section><section style="margin-top: 24px;"><strong>关于日志的小结和回顾。</strong>出于性能原因，可能会关闭数据库日志，以避免额外的磁盘访问延迟或节省宝贵的存储资源。即使我们打开了日志，所有访问都使用单个<strong>服务帐户</strong>——不论是来自我们的微服务的访问，还是来自非应用程序型工具的访问（如DBA、SRE、DevOps工具）。总之，数据库日志不包含用户身份信息，所以无法帮助我们回答<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">“谁访问了数据？” 这个</span>问题。<br/></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">既然无解，请向前辈(应用程序)学习<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin-top: 8px;">或许，你以为没辙了。但还可以向前辈（应用程序）学习。</section><section style="margin-top: 8px;">我们知道，<strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">Web</span>应该程序<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">使用单点登录 (SSO) ，</span>完美地解决了身份问题</strong>。我们来看看，它是如何做到的。<br/></section><section style="margin-top: 8px;"><strong>SSO的工作流需要用户、应用程序、身份提供者 (IdP) 这三方的共同努力</strong>：<br/></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="margin-top: 0px;">用户启动Web应用程序</p></li><li><p style="margin-top: 0px;">用户点击登录</p></li><li><p style="margin-top: 0px;">浏览器重定向到身份提供者 (IdP) 登录页面</p></li><li><p style="margin-top: 0px;">用户登录到这个受信任的资源</p></li><li><p style="margin-top: 0px;">浏览器重定向回应用程序</p></li><li><p style="margin-top: 0px;">用户完成工作</p></li></ol><section style="margin-top: 8px;">可见，应用程序、身份提供者、用户共同构建了很好的体验：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;"><strong>身份提供者：</strong>将用户凭据安全地存储在一处。身份提供者提供丰富的用户上下文，包括经过验证的身份和组成员资格。</p></li><li><p style="margin-top: 0px;"><strong>应用程序：</strong>接受此令牌，并可以根据用户的组成员资格或其他声明对用户做出授权决定，但Web服务不需要存储凭据或验证用户的电子邮件。</p></li><li><p style="margin-top: 0px;"><strong>用户：<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">如果</span></strong>已经登录到共享的SSO身份提供程序，他们可能会直接被重定向回网站，而无需再次登录。这是一种很棒的用户体验。</p></li></ul><section style="margin-top: 8px;">当我们审视SSO内部的这种机制时，我们看到了一个优雅的机制，即应用程序、身份提供者、用户三者一起工作，来创建这个优雅的解决方案。如果我们查看<strong>微服务的日志</strong>，我们可以看到用户的身份、组成员资格、请求URL、响应状态代码、请求持续时间、日期/时间、<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">连接的细节（如<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">源IP等</span>）</span>。</section><section style="margin-top: 8px;">既然<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">SSO</span>已经解决了应用程序的问题，我们是否可以用SSO解决数据库的问题呢？</section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">然而，数据并</strong>没有SSO(单点登录)</strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin-top: 8px;">对于应用程序而言，单点登录 (SSO) 是应用程序的绝佳解决方案，可以获取请求和响应的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>、连接的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>、身份上下文。</section><section style="margin-top: 8px;">那为什么我们不能对数据这么做呢？ <br/></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.46211251435132034" data-w="1742" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=45db6f88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNbRAawNDIKKibXjV9xTwPwK5ducicKq8zwGEaVoYQ8cxlDtZGWGWS6vMXAQNd8UKNvJtDCeuqh6eug%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图1-数据没有SSO（单点登录）<br/></section><section style="margin-top: 8px;">如上图所示：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong>面对Web应用程序</strong>：我们可以轻松地转发给<strong>身份提供者 (IdP)</strong>。借助云资源，我们可以使用OIDC或SAML进行身份验证。</section></li><li><section style="margin-top: 8px;"><strong>面对本地和云中的</strong><span style="color: rgb(61, 167, 66);"><strong>数据资源</strong></span><strong>：</strong>我们却一下子回到了<strong>石器时代</strong>，因为<strong>许多流行的数据库并不支持SAML/OIDC协议</strong>。尽管Snowflake或Redshift这样的<strong>现代数据库</strong>的确可以通过Okta或IAM支持原生SSO，但大多数业务用户使用<strong>BI工具</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">（如Looker、Tableau、Thoughtspot等）通过<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">单个</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">服务帐户</strong>来</span>访问数据，所以仍然看不清这些工具背后的真实用户。</section></li></ul><section style="margin-top: 8px;">简言之，应用程序有SSO，但数据没有SSO。<br/></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">07</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">既然没有数据SSO，那就创造一个</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><p>让我们从应用程序的SSO解决方案中学习，并设计能够为数据提供身份上下文的日志记录解决方案。</p><section style="margin-top: 8px;">我们先列举我们理想中的日志记录解决方案：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0px;">SSO用户名</p></li><li><p style="margin-top: 0px;">SSO组</p></li><li><p style="margin-top: 0px;">SQL查询</p></li><li><p style="margin-top: 0px;">结果行数</p></li><li><p style="margin-top: 0px;">客户端连接的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span></p></li><li><p style="margin-top: 0px;">日期和时间</p></li></ul><section style="margin-top: 8px;">这正是我们想要的信息：SQL查询、响应的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>、日期和时间、连接的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>、用户身份。</section><section style="margin-top: 8px;"><strong>这也正是我们通过启用SSO的应用程序所能获得的数据</strong>。我们得到经过身份验证的用户和组、请求URL、响应状态代码、返回的字节数、用户的源IP、查询的日期和时间。</section><section style="margin-top: 8px;">如果我们的数据日志中有这些<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>，我们就可以明确而自信地回答问题——谁访问了我们的数据？</section><section style="margin-top: 8px;">那么，我们该如何获得数据存储的这种详细程度？让我们采用<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据访问平台<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">或</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">者称为</span></strong><span style="color: rgb(172, 57, 255);"><strong>数据安全平台（DSP）</strong></span>。</section><p><br/></p><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">08</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">答案：具备数据SSO的数据访问平台</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><p><br/></p><section style="margin-top: 8px;">我们的方案是一个<span style="color: rgb(0, 0, 0);"><strong>数据安全平台（DSP）</strong></span>，它必须是一个<strong>身份</strong><strong>联合访问控制系统</strong>，也必须<strong>能够</strong><strong>将SSO带入数据网格</strong>。</section><section style="margin-top: 8px;">由于数据访问需要区分<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">应用程序访问场景</strong>和<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">非应用程序访问场景</strong></strong>，故需区分两种场景，分别进行应对。</section><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><strong>1）应用程序场景的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 2px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">数据SSO</strong></span></strong></span></strong></strong></strong></strong></strong></strong></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.45081967213114754" data-w="1830" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=64313e1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNbRAawNDIKKibXjV9xTwPwKb8MLHpoy4nUXxlDZteS5DR3uNd8pT9ZMWdE9HekToxjlgqTVLhPibaw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图2-传统方案 vs. 数据SSO方案</section><section style="margin-top: 8px;">在上图中，左侧是DSP之前的场景；在右侧，我们添加了<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>来支持身份上下文日志记录。</section><section style="margin-top: 8px;"><strong>在左侧（传统方案）</strong>：前端向SSO提供者进行身份验证，并检索包含所有 SSO 组和其他声明的 JWT（JSON Web Token）。应用程序可以在微服务之间传递此身份验证<strong>令牌</strong>，以验证用户的身份并做出授权决策。但是，<strong>一旦微服务接触到数据，它就会切换到共享</strong><span style="color: rgb(61, 167, 66);"><strong>服务帐户</strong></span><strong>，于是身份上下文就丢失了</strong>。</section><section style="margin-top: 8px;"><strong>在右侧（数据SSO方案）</strong>：增加了<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP（数据安全平台）<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">来支持身份上下文日志记录</span></span>。我们使用相同的SSO身份验证机制，检索相同的JWT，并通过微服务传递此身份验证令牌。然后，<strong>我们要做一些新颖的事情：我们还</strong><span style="color: rgb(172, 57, 255);"><strong>将这个身份验证令牌传递给DSP的</strong><strong>Sidecar（边车）代理</strong></span>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>捕获查询请求和响应的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>，以及用户身份的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>将该查询操作，代理到数据存储，并将结果返回给应用程序。也就是说，通过使用<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>，我们可以<strong>通过数据层保留用户身份</strong>。</section><section style="margin-top: 8px;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;">2）非应用程序型场景的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 2px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">数据SSO</strong></span></strong></span></strong></strong></strong></strong></strong></strong></section><section style="margin-top: 8px;">注意到，许多数据访问场景并不经过应用程序：<strong>SRE、DBA和其他人可以直接连接到数据存储</strong>。所以，现在让我们来看看通过终端（terminal）或其他专用连接的数据访问。</section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.4079173838209983" style="text-align: center;" data-type="png" data-w="1743" src="https://wechat2rss.xlab.app/img-proxy/?k=0767bcb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNbRAawNDIKKibXjV9xTwPwKK1ovvGYN8icAgABBv5FfsRD2khPxm1Oo3gybdUAEfq8Ut1D2ZtAhGFA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;">图3-传统方案 vs. 数据SSO方案</section><section style="margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">在左侧（传统方案）</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">：</span>用户直接连接到数据库。他们很可能使用<strong>共享服务帐户</strong>，从而导致用户身份丢失。<br/></section><section style="margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">在右侧（数据SSO方案</strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">）</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">：</span>用户通过<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>门户，登录到他们选择的SSO提供商。从那里，他们获得了一个<strong>令牌</strong>，用于<strong>向DSP的Sidecar</strong>验证他们的身份。所以，<strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP可以</span></strong>捕获查询请求和响应的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">细节</span>以及用户身份。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">然后，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DSP</span>将该查询操作，代理到数据存储。</section><section style="margin-top: 8px;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;">3）结论：具有数据SSO的DSP</strong></section><section style="margin-top: 8px;"><strong>对于应用程序和非应用程序的数据访问，DSP</strong><strong>都可以在数据访问过程中捕获</strong><span style="color: rgb(172, 57, 255);"><strong>用户身份</strong></span>。也<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">正是在</span><span style="margin: 0px;padding: 0px;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;outline: 0px;max-width: 100%;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: normal;caret-color: rgba(0, 0, 0, 0);float: none;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline !important;">DSP</span><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">日志中，我们找到了我们正在寻找的东西：</span><strong style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">用户身份</strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">！</span></section><section style="margin-top: 8px;"><strong>借助DSP</strong>，我们可以使用各种<strong>身份</strong><strong>联合访问控制</strong>，如Okta Azure Active Directory、G-Suite等；也可以连接到<strong>各种数据存储</strong>，如MariaDB、MongoDB、SQL Server等；<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;caret-color: rgba(0, 0, 0, 0);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">还</span>可以将日志发送到您选择的<strong>SIEM平台</strong>，如ELK、Splunk、DataDog等。</section><section style="margin: 8px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="letter-spacing: 0.544px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">有了DSP的Sidecar代理，我们就可以使用标准SSO工具，向我们的数据库进行身份验证</strong><span style="letter-spacing: 0.544px;">。应用程序用户和非应用程序用户（如SRE、DBA、部署工具）都可以通过SSO进行身份验证。</span><span style="outline: 0px;max-width: 100%;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: normal;caret-color: rgba(0, 0, 0, 0);box-sizing: border-box !important;overflow-wrap: break-word !important;">DSP</span><span style="letter-spacing: 0.544px;">收集的日志包括查询请求、响应行数、所用时间、连接的</span><span style="outline: 0px;max-width: 100%;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;">细节</span><span style="letter-spacing: 0.544px;">（如</span><span style="outline: 0px;max-width: 100%;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;">客户端IP等</span><span style="letter-spacing: 0.544px;">），以及最重要的SSO用户和组。</span></section><section style="margin: 8px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">谁访问了我们的数据？<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">有了具备<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据SSO能力的</strong>DSP</strong><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">，我们就能知道</strong>。</section><section style="margin-top: 8px;"><br/></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">（本篇完）</p><section style="margin-bottom: 0px;"><br/></section><section style="margin-bottom: 0px;">本文的封面来自于下面这本书：</section><section style="margin-bottom: 0px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="1.3021680216802167" data-w="738" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fdad4e3d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPiaAJRvmhWWmicrFZ2w609OMLLtI6BrPkWvxQib4icMXYYIPTcic1Zt41TBx6a9DeUHdiaEx22u1uCmnJQ%2F640%3Fwx_fmt%3Dpng"/></section>



<p><a href="2247494874">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6afaf545&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494874%26idx%3D1%26sn%3Ddb320cee01958cdcd7ef1cec394c32f4%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 04 Sep 2022 06:06:00 +0800</pubDate>
    </item>
    <item>
      <title>美国国防工业网络保护框架和启示</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494863&amp;idx=1&amp;sn=fa7a0f699a289a1b99178c5d2e2e81bb</link>
      <description>大开眼界</description>
      <content:encoded><![CDATA[<p>
原创 <span>启承 &amp;amp; 柯学</span> <span>2022-08-21 12:51</span> <span style="display: inline-block;">北京</span>
</p>

<p>大开眼界</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2d004745&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPMbbqibztO5rflrPDo5aYbQIKDtKCXfaDLGJ2stDJDAbmEfnQAzFAibiaib4cNXveHIFesrEH5QIuPA9g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<strong>70</strong><span style="color: rgb(0, 0, 0);"><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>10</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t"><p style="text-align: left;margin-top: 10px;"><strong><span style="font-size: 17px;">兰德公司</span></strong><span style="font-size: 17px;">基于对美国国防工业的研究考察，提出了关于国防工业网络安全保护的鲜明观点，比如：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-align: left;"><strong>安全</strong><span style="color: rgb(172, 57, 255);"><strong>预算</strong></span><strong>比例</strong>：国防工业公司应该将其IT预算的<span style="color: rgb(172, 57, 255);"><strong>22%</strong></span>用于网络安全；而对于易遭受网络攻击的公司，则应该进一步<strong>提高</strong>安全预算的比例。</p></li><li><p style="text-align: left;"><strong>从</strong><span style="color: rgb(172, 57, 255);"><strong>监管</strong></span><strong>到</strong><span style="color: rgb(172, 57, 255);"><strong>服</strong></span><span style="color: rgb(172, 57, 255);"><strong>务</strong></span>：国防工业中小型公司无力承担应该投入的网络安全资源，所以国防部仅依靠<strong>纯监管</strong>方式，难以提升DIB公司的整体安全防护能力；<strong>管理层</strong>还应为中小企业提供<strong>免费/廉价的安全服务</strong>，而<strong>云服务</strong>是最具成本效益的选项。</p></li><li><p style="text-align: left;"><span style="color: rgb(172, 57, 255);"><strong>统一</strong></span><strong>保护计划</strong>：必须采取统一保护计划（而非<strong>各自为战</strong>），来提升DIB中小型公司的网络安全能力，该计划的核心是<strong>优惠政策</strong>和<strong>数据交换</strong>。</p></li></ul><section style="text-align: left;margin-top: 8px;"><span style="font-size: 17px;">在其洞察结果的基础上，</span><span style="margin: 0px;padding: 0px;font-size: 17px;">兰德公司进一步提出了</span><span style="color: rgb(172, 57, 255);"><strong>国防工业基础网络保护计划（DCP2）</strong></span><span style="font-size: 16px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">框架</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。并通过严谨细致的<strong>分类方式</strong>（四个维度：大型公司 vs. 小型公司；本地网络部署 vs. 云网络部署；国防部安全运营中心 vs. 商业公司安全运营中心；高价值敏感信息 vs. 中等价值<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">敏感</span>信息）和五颜六色的<strong>部署拓扑</strong>，将其防护思想展示得淋漓尽致。</span></span></section><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">毫无疑问，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">兰德公司的</span>洞察结论和保护框架，对我国国防军工企业的网络安全保护具有重要借鉴意义。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">兰德</span>报告的下载地址见文末。</span></span></p></section></section></section></section></section><p style="margin-top: 8px;"><strong><span style="text-align: left;">关键词</span></strong><span style="text-align: left;">：</span><span style="color: rgb(172, 57, 255);"><strong>DIB</strong></span><span style="text-align: left;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">（<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">国防工业基础</span>）</span>；<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DCP2（<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">国防工业基础网络保护计划</span>）；<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">CUI（</span>受控非密信息）；CST（网络安全工具）；</span></span></p><section style="text-align: center;margin-top: 15px;margin-bottom: 0px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><section style="margin-top: 15px;margin-bottom: 0px;"><strong>1.国防工业基础(DIB)的定义<br/></strong></section><section style="text-indent: 2em;">1）什么是国防工业基础<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">(DIB)</span></section><section style="text-indent: 2em;">2）国防工业基础有多庞大</section><p><strong>2.国防工业基础网络保护计划(DCP2)框架</strong></p><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;">1<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">）</span>框架选项和部署说明</section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;">2）<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">国防工业基础(DIB)之安全部署</span>现状</section><section style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 2em;">3）<span style="color: rgb(172, 57, 255);"><strong>国防工业基础网络保护计划(DCP2)</strong></span>之安全部署场景</section><p><strong>3.洞察和启示</strong></p><section style="text-indent: 2em;">1<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>易遭受网络攻击的公司，应该<strong>提高安全预算的比例</strong></section><section style="text-indent: 2em;">2<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>DIB公司应该将其<strong>IT预算的</strong><span style="color: rgb(172, 57, 255);"><strong>22%</strong></span><strong>用于网络安全</strong></section><section style="text-indent: 2em;">3<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>DIB<strong>中小型公司</strong><span style="color: rgb(172, 57, 255);"><strong>无力承担</strong></span>应该投入的网络安全资源</section><section style="text-indent: 2em;">4<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>国防部仅依靠<span style="color: rgb(172, 57, 255);"><strong>纯监管</strong></span>方式，难以提升DIB公司的整体安全防护能力</section><section style="text-indent: 2em;">5<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>当前国防部提出的网络安全成熟度模型认证(CMMC)程序仍有不足</section><section style="text-indent: 2em;">6<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>必须采取<strong>统一保护计划</strong>，来提升DIB中小型公司的网络安全能力</section><section style="text-indent: 2em;">7<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>国防工业基础网络保护计划(DCP2)的核心是<span style="color: rgb(172, 57, 255);"><strong>优惠政策</strong></span><span style="color: rgb(0, 0, 0);">和</span><span style="color: rgb(172, 57, 255);"><strong>数据交换</strong></span></section><section style="text-indent: 2em;">8<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>网络安全的<strong>管理层</strong>，需要提供<span style="color: rgb(172, 57, 255);"><strong>安全服务</strong></span>功能</section><section style="text-indent: 2em;">9<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span><span style="color: rgb(172, 57, 255);"><strong>网络威胁共享服务</strong></span>，并非想象的那么容易</section><section style="text-indent: 2em;">10<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span><span style="color: rgb(172, 57, 255);"><strong>向云迁移</strong></span>是最具成本效益的选项</section><section style="margin-top: 16px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">国防工业基础（DIB）的定义</strong><strong style="margin: 0px;padding: 0px;text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 16px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></section><p style=""><strong><span lang="EN-US" style="font-family: Helvetica, sans-serif;">1）</span><span style="font-family: 宋体;">什么是国防工业基础</span></strong></p><section style="margin-top: 8px;"><strong><span style="font-family: 宋体;">国防工业基础（DIB）</span></strong><span style="font-family: 宋体;">是一组提供<strong>国防工业能力</strong>的私营和公有公司（从小公司到大公司）。<strong>国防工业能力</strong>是“设计、开发、制造、维修、保障国防部产品及其必要子系统和组件所需的技能和知识、流程、设施、设备”。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">国防工业基础（DIB）有两个组成部分：</span></section><ol class="list-paddingleft-1" style="list-style-type: lower-alpha;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;"><span lang="EN-US" style="font-family: Wingdings;"></span><strong><span style="font-family: 宋体;">国内</span></strong><span style="font-family: 宋体;">制造业和国防工业基础；</span></span></section></li><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><strong><span style="font-size: 17px;"><span style="font-family: 宋体;">全球</span></span></strong><span style="font-size: 17px;"><span style="font-family: 宋体;">制造业和国防工业基础。</span></span></section></li></ol><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5009548058561426" data-s="300,640" data-w="1571" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d0ef067e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKn5M0oDbLUqBYc71NhySueQThLae8g8lugh7xNPbP5sxKT3iaZqmqhiag%2F640%3Fwx_fmt%3Dpng"/></section><p style="text-align: center;"><strong><span style="font-family: 宋体;">图1-国防部的国防工业基础（DIB）的范畴</span></strong></p><section style="margin-top: 8px;"><strong><span style="font-family: 宋体;font-size: 17px;">国内DIB</span></strong><span style="font-family: 宋体;font-size: 17px;">包括来自小、中、大公司的产品和服务的生产者。进一步划分为<strong>私营</strong>机构和<strong>国有</strong>工业基础。私营机构拥有一些主要的系统集成商；国有工业基础包括政府所有、政府运营的实体和政府所有、承包商经营的实体。</span></section><section style="margin-top: 8px;"><strong><span style="font-family: 宋体;font-size: 17px;">全球</span></strong><strong><span style="font-family: 宋体;font-size: 17px;">制造基础</span></strong><span style="font-family: 宋体;font-size: 17px;">由位于其他国家的企业组成，其中一些国家与美国有正式的关系，另一些则没有。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">下图展示了本文所关注的DIB企业类型（如图中红色框所示）：</span></section><section style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.47425301970756517" data-s="300,640" data-w="1573" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f67b1c75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKjZzlMFhoZeiamnRUWVpuSLKgnLyM0ZsQWGVkIvK6DibTiaaKoynB9NT7w%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">图2-本文的研究对象（由红色框标记）</span></strong></span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">图中红色框表示兰德报告的研究重点。在国内基础中，兰德报告的私营机构关注重点是为国防部进行研究的中小型技术行业公司。在兰德报告的研究中，国防工业基础（DIB）的小型公司是年收入在 1 亿美元以下的公司，中型公司是年收入在 1 亿美元到 5 亿美元之间的公司，而大型公司是年收入在 5 亿美元以上的公司。以下是 2018 财年的一些例子：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;font-family: 宋体;">国防工业基础（DIB）</span><span style="font-family: 宋体;font-size: 17px;color: rgb(61, 167, 66);"><strong>小型</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>公</strong><strong>司</strong>：如MaXentric
Technologies，美国国防部高级研究计划局（DARPA）承包商，雇员超过 50 人，年收入 500 万-1000万美元；</span></section></li><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;font-family: 宋体;">国防工业基础（DIB）</span><span style="font-family: 宋体;font-size: 17px;color: rgb(61, 167, 66);"><strong>中型</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>公司</strong>：如佐治亚理工学院研究公司，来自国防部的收入约为 3.93 亿美元；<strong>微软公</strong>司，商业高科技公司，来自国防部的收入大约 4 亿美元；</span></section></li><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;font-family: 宋体;">国防工业基础（DIB）</span><span style="font-family: 宋体;font-size: 17px;color: rgb(61, 167, 66);"><strong>大型</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>公司</strong>：如<strong>波音</strong>，飞机领域的主承包商，雇员 137000人，年收入 1010 亿美元，来自国防部的收入约 270 亿美元；洛克希德·马丁公司，飞机、电子、雷达、电子战领域的主承包商，雇员 105000 人，年收入 538 亿美元，来自国防部的收入约为 390 亿美元。</span></section></li></ul><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><span lang="EN-US" style="font-family: Helvetica, sans-serif;">2）</span><strong><span style="font-family: 宋体;">国防工业基础有多庞大</span></strong></span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;">总体上看，拥有巨额收入的<strong>顶级防务公司</strong>在DIB中占<strong>主导地位</strong>，但在整个DIB公司的数量中<strong>只占很小比例</strong>。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;">兰德公司认为，DIB供应链的规模分布与美国整体经济中的企业规模分布没有显著差异。因此，可以使用美国联邦采办数据系统，来估计国防部承包商的数量和来自国防部的收入（国防部对公司的年度拨款）。如下图所示，估计DIB公司的总数大约为<strong>7.2万</strong>家。（美国国防部2022年的最新官方说法是大约</span><span style="font-family: 宋体;color: rgb(172, 57, 255);"><strong>22万</strong></span><span style="font-family: 宋体;">家公司）</span><br/></section><section style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5725490196078431" data-s="300,640" data-w="1275" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=baf81b37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKMfgqHTaVe6UttIQQM2gpWa9K6zjDOYyicCyv3HlcpGQ01cic8wTuT0yQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">图3-国防工业基础（DIB）公司规模分布</span></strong></span></section><section style="margin-top: 16px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">国防工业基础网络保护计划（DCP2）框架</strong><strong style="margin: 0px;padding: 0px;text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 16px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></section><p style=""><span lang="EN-US" style="font-family: Helvetica, sans-serif;">1）</span><strong><span style="font-family: 宋体;">框架选项和部署说明</span></strong></p><section style="margin-top: 8px;"><span style="font-family: 宋体;">兰德报告为国防工业基础网络保护计划（DCP2）提供了</span><strong style="font-family: 宋体;">多个框架选项</strong><span style="font-family: 宋体;">。这些选项由</span><strong style="font-family: 宋体;">几个关键因素</strong><span style="font-family: 宋体;">定义：</span></section><ul class="list-paddingleft-1" style="list-style-type: square;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">第1因素</span></strong><span style="font-family: 宋体;">：国防部的</span></span><span style="font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong>作用</strong></span><span style="font-size: 17px;font-family: 宋体;">：直接、间接。分为两个选项：</span></section></li></ul><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">选项A</span></strong></span><span style="font-size: 17px;font-family: 宋体;">：<strong>国防部领导</strong>的DIB安全运营中心（SOC）；</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">选项B</span></strong></span><span style="font-size: 17px;font-family: 宋体;">：<strong>商业公司主导</strong>的安全运营中心（SOC）；</span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: square;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">第2因素</span></strong><span style="font-family: 宋体;">：DIB公司的</span></span><span style="font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong>规模</strong></span><span style="font-size: 17px;font-family: 宋体;">：大型、中型、小型；</span></section></li></ul><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><strong><span lang="EN-US" style="font-family: 宋体;">DIB</span></strong></span><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong><span lang="EN-US" style="font-size: 17px;font-family: 宋体;">小型</span></strong></span><span style="font-size: 17px;"><strong><span lang="EN-US" style="font-family: 宋体;">公司</span></strong><span lang="EN-US" style="font-family: 宋体;">：年收入在1亿美元以下；</span></span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><strong><span style="font-size: 17px;font-family: 宋体;">DIB</span></strong><span style="color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">中型</span></strong></span><strong><span style="font-size: 17px;font-family: 宋体;">公司</span></strong><span style="font-size: 17px;font-family: 宋体;">：年收入在1亿到5亿美元之间；</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><strong><span style="font-size: 17px;font-family: 宋体;">DIB</span></strong><span style="color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">大型</span></strong></span><strong><span style="font-size: 17px;font-family: 宋体;">公司</span></strong><span style="font-size: 17px;font-family: 宋体;">：年收入在5亿美元以上。</span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: square;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">第3因素</span></strong><span style="font-family: 宋体;">：DIB公司非密网络所在的</span></span><span style="font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong>位置</strong></span><span style="font-size: 17px;font-family: 宋体;">：</span></section></li></ul><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-family: 宋体;font-size: 17px;color: rgb(0, 82, 255);"><strong>本地网络</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>部署</strong>；</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;font-family: 宋体;color: rgb(0, 82, 255);"><strong>云网络</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>部署</strong>；</span></p></li></ul><ul class="list-paddingleft-1" style="list-style-type: square;"><li><section style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">第4因素</span></strong><span style="font-family: 宋体;">：DIB公司的受控非密信息（CUI）</span></span><span style="font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong>级别</strong></span><span style="font-size: 17px;font-family: 宋体;">：</span></section></li></ul><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">高</span></strong></span><strong><span style="font-size: 17px;font-family: 宋体;">价值</span></strong><span style="font-size: 17px;font-family: 宋体;">（HV）；</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-family: 宋体;font-size: 17px;color: rgb(0, 82, 255);"><strong>中等</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>价值</strong>（MV）。</span></p></li></ul><section style="margin-top: 8px;"><span style="color: rgb(172, 57, 255);"><strong><span style="font-family: 宋体;">网络部署图</span></strong></span><span style="font-family: 宋体;">展示了国防工业基础网络保护计划（DCP2）中的每个工具或功能在</span><strong style="font-family: 宋体;">不同规模</strong><span style="font-family: 宋体;">的DIB公司网络上的部署情况：</span><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><span style="font-family: 宋体;">大型公司；</span></span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><span style="font-family: 宋体;">具有云环境的大型公司；</span></span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><span style="font-family: 宋体;">小型公司；</span></span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><span style="font-family: 宋体;">具有云环境的小型公司。</span></span></p></li></ul><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">兰德报告对网络安全工具集（CST）进行了分类，以便将其映射到建议的国防工业基础网络保护计划（DCP2）。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;">网络部署图的<strong>颜色说明</strong>：</span><br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-top: 0px;"><span style="color: rgb(255, 0, 0);"><strong><span style="font-family: 宋体;">红色</span></strong></span><span style="font-family: 宋体;">：显示了<strong>DIB公司自购</strong>的网络安全工具集（CST）；</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;color: rgb(61, 167, 66);"><strong><span style="font-size: 17px;font-family: 宋体;">绿色</span></strong></span><span style="font-size: 17px;font-family: 宋体;">：显示了<strong>国防工业基础网络保护计划（</strong></span><span style="font-family: 宋体;font-size: 17px;color: rgb(61, 167, 66);"><strong>DCP2</strong></span><span style="font-size: 17px;font-family: 宋体;"><strong>）提供</strong>的网络安全工具集（CST），如自动打补丁、电子邮件筛选、终端检测和响应（EDR）等。</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;"><strong><span style="font-family: 宋体;">黑色</span></strong><span style="font-family: 宋体;">：表示<strong>威胁</strong>；</span></span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 0px;"><span style="font-size: 17px;color: rgb(0, 82, 255);"><strong><span style="font-size: 17px;font-family: 宋体;">蓝色</span></strong></span><span style="font-size: 17px;font-family: 宋体;">：表示<strong>网络资源</strong>。</span></p></li></ul><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;">所以，以下网络部署拓扑图中的<strong><span style="color: rgb(61, 167, 66);">绿色</span></strong>部分，都是国防工业基础网络保护计划（DCP2）的内容，值得特别关注。</p><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><br/></p><p style="margin-right: 0cm;margin-left: 0cm;margin-top: 8px;"><strong><span style="font-size: 17px;"><span style="font-family: 宋体;">2）国防工业基础（DIB）之安全部署现状</span></span></strong></p><section style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5506736965436438" data-s="300,640" data-w="1707" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=085ab895&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKMZ1VavUzOmkwgn4MlRMgN89xpCEtp8ILvQibibnxyRg3etOEiciaCKbYtg%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-top: 8px;">图4-国防工业基础（DIB）<span style="text-align: justify;">现状：大型公司 vs. 小型公司</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">通过该图明显可见，总体来看，<strong>大型公司</strong>通常使用更多、功能更强的网络安全工具集（CST）；而<strong>小型公司</strong>使用更少的功能更弱的工具，比如缺少SOC、自动补丁、威胁情报、邮件安全、数据过滤、网络访问控制、EDR等安全能力。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">特别是，大多数DIB<strong>小型公司</strong>，通常缺少安全运营中心（SOC）和内部安全信息和事件管理（SIEM）能力，因此难以有效应对复杂网络攻击或高级持续性威胁（APT）的挑战。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></section><p style="margin: 8px 0cm 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">3）</span></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"></span>国防工业基础网络保护计划（DCP2）之安全部署场景<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: justify;"></span></span></span></strong></p><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"></span></section><section style="margin-top: 8px;text-align: left;"><strong>3.1）大型DIB公司场景</strong></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5513613861386139" data-s="300,640" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;text-align: center;" data-type="png" data-w="1616" src="https://wechat2rss.xlab.app/img-proxy/?k=12db090a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKqGTYoibkUF3Gic1IBab7D5x4ONo0wAteoEY7c7BmPJiasS7Qe1cye6B1g%2F640%3Fwx_fmt%3Dpng"/><span style="margin: 0px;padding: 0px;text-align: center;"></span></section><section style="margin: 8px 0px 0em;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;">图5-大型公司网络：现状 vs. 选项A</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">对于<strong style="margin: 0px;padding: 0px;">大型公司</strong>而言，由于大型公司通常已经自建了大部分的安全能力（见左图，以红色标记），故通过DCP2提供的安全能力（以绿色标记）并不多，主要是DLP、自动补丁、Web安全工具等（见右图，以绿色标记）。右图（选项A）中，还</span><span style="font-family: 宋体;">连接到</span><strong style="font-family: 宋体;">国防部领导</strong><span style="font-family: 宋体;">的DIB安全运营中心</span><span style="font-family: 宋体;">。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;"><br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5489467162329615" data-s="300,640" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;text-align: center;" data-type="png" data-w="1614" src="https://wechat2rss.xlab.app/img-proxy/?k=00f85748&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKoBcNxWfOjSq6aVy290wwnfPAp5tmKPn5lI1j6DbCEFAEdc8CFIvufw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin: 8px 0px 0em;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;">图6-大型公司网络：选项A vs. 选项B</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">上图显示了选项A和选项B的区别：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">两者的安全控制几乎是</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">完全相同的；</span></span></p></li><li><p style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">但</span></span>选项A（左图）仅使用了<strong>国防部</strong>领导的DIB安全运营中心；</p></li><li><p style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">而选项B<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">（右图</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）除了</span>还增加了<strong>商业</strong>安全运营中心，并且将网络威胁情报、<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">高级防火墙</span>能力转交商业<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">安全运营中心来提供。</span></p></li></ul><p><br/></p><section style="margin-top: 8px;text-align: left;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5601039636127355" data-s="300,640" style="text-align: center;" data-type="png" data-w="1539" src="https://wechat2rss.xlab.app/img-proxy/?k=2c1bb6bc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKrkbxYiclAbGz3rOib7nNhOHznqQbkHpEWR3O9cwTPaBiaODsKna5YDqWw%2F640%3Fwx_fmt%3Dpng"/><br/><span style="font-family: 宋体;font-size: 17px;"></span></section><section style="margin-top: 8px;text-align: center;"><span style="font-family: 宋体;font-size: 17px;"></span></section><section style="margin-top: 8px;text-align: center;"><span style="font-family: 宋体;font-size: 17px;">图7-大型公司<span style="color: rgb(51, 51, 51);font-family: 宋体;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">（</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: 宋体;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">选项A</span><span style="color: rgb(51, 51, 51);font-family: 宋体;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>：本地网络 vs. 云网络</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;">上面左、右两图的安全能力几乎是相同的，其主要差异在于是否上云。而上云情况下主要是由云服务提供商（</span><strong style="font-family: 宋体;">CSP</strong><span style="font-family: 宋体;">）提供对DIB公司云中</span><strong style="font-family: 宋体;">飞地</strong><span style="font-family: 宋体;">（其中包含邮件、门户网站等）的安全防护。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;"><strong style="margin: 0px;padding: 0px;">3.2）小型DIB公司场景</strong></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"></span></section><section style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5274725274725275" data-s="300,640" data-w="1729" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=394bd2f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGK4VTnpM9soz4G2lhR4c3A11UCMPFaIdiaHZUD0yjskUpOUduJYaCv9pQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-bottom: 0em;margin-top: 8px;">图8-<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">小型DIB公司的</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">本地网络（选项A）：</span>拥有高价值<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">CUI</span> vs. 中等价值CUI</section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">如图所示，由<strong>红色</strong>标记的DIB公司自购的网络安全工具非常少，这是现状；而<strong>绿色</strong>标记的DCP2网络安全工具就非常多，极大补充了DIB小型公司的安全能力。这也正是国防工业基础网络保护计划（DCP2）的目的所在。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">前面提到，大多数DIB小型公司，通常缺少安全运营中心（SOC）和内部SIEM能力。而通过参与国防工业基础网络保护计划（DCP2），DIB小型公司将可以由一个集中式的DIB安全运营中心（SOC）提供SIEM功能，从而具备了一些<strong>要求最高、劳动力最密集</strong>的网络安全功能：如威胁分析、数据关联、数据汇总、警报分类。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">上面左、右两图的主要区别在于：在访问控制方面，右侧的中价值公司采用了常见的网络访问控制（MFA），而左侧的高价值公司则采用了<strong>密码安全MFA</strong>，提高了安全标准；此外，在数据安全方面，右侧的中价值公司采用了<strong>数据过滤程序</strong>，而左侧的高价值公司则采用了<strong>DLP（数据防泄漏）</strong>，也提高了安全标准。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5216627634660421" data-s="300,640" data-w="1708" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e87ae2da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKYurRwyHORteB1bGkuNWu8j7YibTGluvnEWjpE2gPC5qfrhAQLbbVCCA%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-bottom: 0em;margin-top: 8px;">图9-<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">小型DIB公司的云网络（选项A）：</span>拥有高价值<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">CUI</span> vs. 中等价值CUI</section><section style="margin-top: 8px;text-align: center;"><span style="font-family: 宋体;font-size: 17px;"></span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">该图的最大特色是，红色的自购安全控制全部消失，表明<strong>所有安全控制皆由DCP2计划提供</strong>（绿色标记）。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">上面左、右两图的主要区别在于：右侧的中价值公司采用了<strong>数据过滤程序</strong>；而左侧的高价值公司则采用了<strong>DLP（数据防泄漏）</strong>，提高了安全标准。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;">对于后面的各种场景图，请自行对比，不再赘述：</span></section><p style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.534617700180614" data-s="300,640" data-w="1661" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a856ddb9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGK3ewAjyNXvPOfOSuVKBbol4fc4uIrSdZNZo5iaYZxwicgcgRHibC27afBQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-top: 8px;">图10-<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">小型DIB公司的本地网络（选项B）：</span>拥有高价值<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">CUI</span> vs. 中等价值CUI</p><p style="text-align: center;margin-top: 8px;"><br/></p><p style="text-align: center;margin-top: 8px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5480710349050827" data-s="300,640" data-w="1633" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=625de266&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKnqzbic0pxCGEZ89jAFNkN0hldY8FPlptYkSeibXMKCum7qOKr8Wia86Ug%2F640%3Fwx_fmt%3Dpng"/></p><section style="text-align: center;margin-bottom: 0em;margin-top: 8px;">图11-<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">小型DIB公司的云网络（选项B）：</span>拥有高价值<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">CUI</span> vs. 中等价值CUI</section><p style="text-align: center;margin-top: 8px;"><br/></p><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5412621359223301" data-s="300,640" data-w="1648" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f656d918&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKfELvru6Y9jmtn5SeoSXE0RR98r7ia0vYAWOpDbzicIpbgA2jwXl248Pg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图12-拥有高价值CUI的小型DIB公司的本地网络：选项A vs. 选项B</section><section style="margin-top: 8px;text-align: center;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5481299816063765" data-s="300,640" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;" data-type="png" data-w="1631" src="https://wechat2rss.xlab.app/img-proxy/?k=4a3dd960&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKrSPBAMR3OOey15w4lmjXIkE0ic00HtBeQzdeDnloxhX4IN06gQWRbnA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin: 8px 0px 0px;padding: 0px;text-align: center;">图13-拥有高价值CUI的小型DIB公司的云网络：选项A vs. 选项B</section><section style="margin: 8px 0px 0px;padding: 0px;text-align: center;"><br style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5370705244122965" data-s="300,640" data-w="1659" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=470042fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKjdoTRIKl7SXMn58ib7htv2wd6wfTa3ubNNXlJ2aARrzA8jrVZtOwKtg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图14-拥有中等价值CUI的小型DIB公司的本地网络：选项A vs. 选项B</section><section style="margin-top: 8px;text-align: center;"><br/></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5434650455927051" data-s="300,640" data-w="1645" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a85a96d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNGcIicIQsTPZHfteGcz1rGKy6xtbkONEoFbLI9k90bDoicfZVic6jhG9bIicCF6EriaX06NgMZPdQTsfw%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-bottom: 0em;margin-top: 8px;">图15-拥有中等价值CUI的小型DIB公司的云网络：选项A vs. 选项B</section><p style="margin-top: 16px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">洞察和启示</strong><strong style="margin: 0px;padding: 0px;text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 16px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/><span lang="EN-US" style="font-family: Helvetica, sans-serif;">1）</span><strong><span style="font-family: 宋体;">易遭受网络攻击的公司，应该提高安全预算的比例</span></strong></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">兰德认为，</span><strong style="font-family: 宋体;">一家公司的网络安全预算必须足够大</strong><span style="font-family: 宋体;">，才能支付网络安全专业人员的工资和福利、网络安全工具集（CST）的软件许可费，以及应对网络安全事件可能需要的额外资金，如额外的工具或服务和来自外部专家或公司的建议。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德同时认为，不论国内外网安市场中安全预算的<strong style="margin: 0px;padding: 0px;">实际比例</strong>如何，当一家公司有较大概率遭受网络攻击时，就应该提高安全预算的比例。考虑到其业务和资产的价值，DIB公司当然属于这类公司，理所应当提高安全预算的比例。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">这一结论启示我们，<strong style="margin: 0px;padding: 0px;">设置安全预算比例，不能只是参考市场平均数字，而要考虑实际面临的威胁和风险状况</strong>。如果确实面临较大网络攻击风险，则在某种程度上有必要“<strong>不计成本</strong>”地提高安全预算比例。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">2）<strong style="margin: 0px;padding: 0px;">DIB</strong></span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">公司应该将其</span></strong><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">IT</span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">预算的</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="font-size: 17px;margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">22%</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">用于网络安全</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">兰德报告中指出，IBM建议有严重网络安全问题的公司将其IT预算的<strong>14%</strong>用于网络安全措施。Forrester数据显示，如果一家公司遭到黑客攻击，它将把IT 预算的<strong>30%</strong>或更多用于网络安全。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德测算结果表明，平均而言，一家DIB公司应该将其<strong style="margin: 0px;padding: 0px;">IT预算的22%用于网络安全</strong><strong>，这是上述14%和30%建议的平均值</strong>。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德认为这个目标是可以接受的，因为已经<strong style="margin: 0px;padding: 0px;">假设有多达一半的DIB可能受到了网络攻击</strong>。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">为了支撑该结论和观点，兰德进行了以下五项分析：</span></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin: 0px 0cm;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: &#34;Courier New&#34;;"></span><span style="margin: 0px;padding: 0px;font-family: 宋体;">网络安全预算估算</span></span></p></li><li><p style="margin: 0px 0cm;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">国防工业基础公司信息技术预算估算</span></span></p></li><li><p style="margin: 0px 0cm;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">网络安全人员工资估算</span></span></p></li><li><p style="margin: 0px 0cm;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">国防工业基础公司小样本特征分析</span></span></p></li><li><p style="margin: 0px 0cm;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">国防工业基础中小型公司网络安全预算估算与建议的比较</span></span></p></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">3）<strong style="margin: 0px;padding: 0px;">DIB</strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">中小型公司无力承担</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">应该投入的网络安全资源</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong><span style="font-family: 宋体;">网络安全是必要的，但也是昂贵的。</span></strong><span style="font-family: 宋体;">一套网络安全工具需要专业人员才能使用，而所需的工具和熟练的专业人员对许多DIB公司来说可能负担不起。此外，管理环境复杂且难以驾驭，即使对于拥有强大网络安全团队的大型公司也是如此。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德分析表明：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">对于DIB小型公司</strong>：要么无法拥有足够的网络安全专业人员，要么无法维护全套的网络安全工具集（CST），几乎不可能同时拥有网络安全专业人员和全套的网络安全工具集（CST）；</span></section></li><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">对于DIB中型公司</strong>：在承担网络安全工具和专业人员成本方面处于更有利的地位，但它们仍面临挑战。</span></section></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">更多的资金未必意味着更多的网络安全</strong>。要保护DIB公司的非密网络，除了花钱购买网络安全工具集（CST），还需要<strong style="margin: 0px;padding: 0px;">有效管理、网络安全最佳实践、员工培训</strong>。然而，如果公司没有足够的钱花在网络安全工具集（CST）和网络安全专业人员身上，这将严重阻碍他们的网络安全努力。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">4）</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">国防部仅依靠</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">纯监管</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">方式，难以提升</span></strong><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">DIB</span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">公司的整体安全防护能力</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">目前国防部防止DIB遭受网络攻击的方法，主要基于<strong>国防联邦采办条例补充规定（DFARS）800-7012</strong>和<strong>NIST SP 800-171</strong>，但这样做并不够。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">兰德报告的成本分析显示，DIB的小型公司和一些中型公司<strong>没有足够资源</strong>，来遵守NIST SP 800-171的合规要求。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">5）</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">当前国防部提出的网络安全成熟度模型认证（</span></strong><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">CMMC</span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">）程序仍有不足</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">国防部推出的</span><strong style="font-family: 宋体;">网络安全成熟度模型认证（CMMC）</strong><span style="font-family: 宋体;">，仍然是</span><strong style="font-family: 宋体;">基于合规性</strong><span style="font-family: 宋体;">的，并将增加DIB公司的成本。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德报告的成本分析表明，大多数DIB的小型公司可能无力负担网络安全成熟度模型认证（CMMC）的网络防御要求。许多中等规模的DIB公司可能面临同样的挑战，特别是如果要求它们达到网络安全成熟度模型认证（CMMC）的最高合规等级的话。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">兰德报告建议的<strong>国防工业基础网络保护计划（DCP2）</strong>，</span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">并非要取代</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">网络安全成熟度模型认证（CMMC）</strong>，<strong>而是</strong><strong style="margin: 0px;padding: 0px;">为了</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">完善</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">这一认证</strong>，帮助改善DIB公司对NIST SP 800-171指南的合规性。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">6）</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">必须采取</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">统一保护计划</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">，来提升</span></strong><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">DIB</span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">中小型公司的网络安全能力</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">一方面，兰德报告称，如果遵循国防部目前的方法，可能无法保护DIB公司在非密网络上拥有的大量受控非密信息（CUI）不受外国对手的攻击。而来自非密网络的持续攻击和关键信息技术的损失，以及重大的经济损失，侵蚀了美国的国防工业基础（DIB），也威胁到美国的长期军事优势。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">另一方面，对于DIB的<strong>小型公司</strong>来说，网络安全专业人员的成本将导致在聘请网络安全专业人员和购买额外的网络安全工具集（CST）上两者不可兼得。许多DIB的<strong>中型公司</strong>也不得不做出类似的决定。即便是当前国防部提出的网络安全成熟度模型认证（CMMC）程序，对许多中小型国防工业基础公司来说可能是负担不起的。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">为了充分保护DIB公司的非密网络，<strong style="margin: 0px;padding: 0px;">需要替代的解决方案</strong>。这个替代方案就是<strong style="margin: 0px;padding: 0px;">国防工业基础网络保护计划（DCP2）</strong>，其目的是推动国防部加强<strong>非密</strong>DIB网络的保护，用来抵御网络空间严重的安全威胁。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">7）</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">国防工业基础网络保护计划（</span></strong><strong style="margin: 0px;padding: 0px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">DCP2</span></strong><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">）的核心是</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;color: rgb(172, 57, 255);margin: 0px;padding: 0px;font-family: 宋体;">优惠政策和数据交换</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">为了系统性解决DIB公司非密网络网络安全防护面临的各种问题，兰德报告建议国防部，建立</span><strong style="font-family: 宋体;">国防工业基础网络保护计划（DCP2）</strong><span style="font-family: 宋体;">，包括：</span></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">改善DIB的</span><span style="font-family: 宋体;margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">监控</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">和<strong style="margin: 0px;padding: 0px;">实时健康状况</strong>；</span></section></li><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">为那些</span><span style="font-family: 宋体;margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">无力负担</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">所需网络安全工具集（CST）和专业人员的公司，改善网络安全；</span></section></li><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">提供</span><span style="font-family: 宋体;margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">数据保护</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">，防止从DIB公司到国防部的敏感企业信息、DIB上的敏感供应链信息、DIB的敏感数据，泄露给对手；</span></section></li><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">为DIB公司提供</span><span style="font-family: 宋体;margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">法律保护</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">，如果DIB公司提供给政府的信息被非预期使用，最小化他们可能承担的责任。</span></section></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">国防工业基础网络保护计划（DCP2）的核心是<strong>优惠政策和数据交换</strong>：</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">一方面是<strong style="margin: 0px;padding: 0px;">优惠政策</strong>：DIB公司参加国防工业基础网络保护计划（DCP2）将是<strong style="margin: 0px;padding: 0px;">自愿</strong>的。参与该计划的DIB公司将同意安装和使用国防部提供的网络安全工具集（CST）。关键在于，<strong style="margin: 0px;padding: 0px;">这些网络安全工具集（CST）将</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">免费提供</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><strong style="margin: 0px;padding: 0px;">，或者以大幅降低的许可价格提供</strong>。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">另一方面是</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">数据交换</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;">：DIB公司将同意向新的DIB安全运营中心（SOC）或专门为DIB服务的商业安全运营中心（SOC），<strong style="margin: 0px;padding: 0px;">提供网络安全工具集（CST）产生的经过清洗的数据，以改善DIB的实时监控和健康状况</strong>。<strong style="margin: 0px;padding: 0px;">这些</strong></span></span><span style="font-family: 宋体;margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">数据包括</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;"><strong style="margin: 0px;padding: 0px;">网络元数据、应用程序元数据、匿名用户帐户元数据、安全警报和匿名系统日志文件</strong>。这些经过清洗的</span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">数据不包括</strong></span><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;"><strong style="margin: 0px;padding: 0px;">DIB公司员工的个人身份信息（PII）、公司专有信息、员工通信，或者任何受控非密信息（CUI）</strong>。<strong style="margin: 0px;padding: 0px;">国防部将免费提供数据清洗程序</strong>，确保只将相关的网络安全数据传输到DIB安全运营中心（SOC）或商业安全运营中心（SOC）。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">管理国防工业基础网络保护计划（DCP2）的<strong>成本很重要</strong>。只有拥有重要受控非密信息（CUI）并向国防部提供关键国防技术的DIB公司，才有资格获得该计划的全部好处。那些主要为国防项目提供大宗商品相关产品的小公司，可能不符合条件。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">8）</span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">网络安全的管理层，需要提供</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">安全服务</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">功能</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">兰德报告认识到国防工业基础网络保护计划（DCP2）会给政府带来新的</span><strong style="font-family: 宋体;">巨大成本</strong><span style="font-family: 宋体;">，也预料到一些反对者可能会争论说，这笔成本应该由私营行业承担，因为他们将在许多方面从国防部提供的网络安全工具集（CST）中受益。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">然而，兰德报告认为<strong style="margin: 0px;padding: 0px;">保护DIB</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">归根结底是美国政府的责任</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">。DIB公司正受到有能力的民族国家的网络攻击，<strong>对手使用的大量资源在许多情况下都远远超过DIB公司的可用资源</strong>。2019年，美国国家安全局（NSA）局长呼吁公共和私营行业团结起来共同应对网络安全威胁：“<strong>指望私营行业能够真正经受住整个国家的集中攻击（而这些国家还正在以一种非常同步的战略路线努力尝试获得优势），我认为这是不现实的</strong>。”</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">就像在其他领域（如司法领域），私营公司应该受到执法机构的保护</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">，使其免受犯罪行为的侵害（例如，由当地警察部门或联邦调查局保护）。DIB公司也有权获得美国政府的某种形式的网络安全保护，尽管这种保护需要公共和私营实体之间的合作才能取得成功。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">国防工业基础网络保护计划（DCP2）的思路，反映了</span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;color: rgb(172, 57, 255);"><strong>使管理层从单纯监管视角转向帮扶弱者的观点</strong></span><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">，值得我们深深的思索。这也许是国防工业基础网络保护计划（DCP2）能够落地的关键思想。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">当然，<strong>精打细算是美国的传统</strong>。兰德报告建议研究网络安全工具（CST）许可成本和模型，其中包括规模经济和价格选项。因为向每个DIB公司提供网络安全工具集（CST）并不是一个合理的经济建议，必须建立门槛和限制，以确定国防部支付的网络安全工具集（CST）数量，并探索不同的网络安全工具集（CST）的<strong>补贴模式</strong>。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span lang="EN-US" style="font-family: Helvetica, sans-serif;">9）</span><span style="color: rgb(172, 57, 255);"><strong><span style="font-family: 宋体;">网络威胁共享服务</span></strong></span><strong><span style="font-family: 宋体;">，并非想象的那么容易</span></strong></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">兰德报告指出，当前</span><strong style="font-family: 宋体;">自愿性的国防部网络威胁共享服务，对许多国防工业基础公司是不可用的</strong><span style="font-family: 宋体;">。因为不是所有的DIB公司都能使用这项服务。为了使用这个网站，DIB公司用户必须使用</span><strong style="font-family: 宋体;">国防部通用访问卡（CAC）</strong><span style="font-family: 宋体;">进行登陆。而一些防务承包商可能没有任何员工拥有这些证件。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">兰德报告提出的解决方案</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;">是，通过实施国防工业基础网络保护计划（DCP2）：</span></span></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><span lang="EN-US" style="margin: 0px;padding: 0px;font-family: &#34;Courier New&#34;;"></span><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">一方面</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;">，通过<strong>DIB安全运营中心</strong>或<strong>商业安全运营中心</strong>，向DIB公司提供动态情报、安全警报、行动建议，以识别和应对高级持续性威胁（APT）入侵；</span></span></section></li><li><section style="margin: 8px 0cm 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">另一方面</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;">，它使<strong>实时威胁情报</strong>能够以目前不可能的方式，在DIB中进行收集和综合。</span></span></section></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">DIB安全运营中心或商业安全运营中心，使用这些数据和其他数据来生成警报，并把这些警报发送回DIB公司，以保护和改善对其网络的监控，免受外部和内部威胁。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">毫无疑问，这种设想为国内网安行业的威胁情报共享，提供了很好的落地思路。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: Helvetica, sans-serif;">10）</span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">向云迁移</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">是最具成本效益的选项</span></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="font-family: 宋体;">实施国防工业基础网络保护计划（DCP2）的</span><strong style="font-family: 宋体;">最具成本效益的选项</strong><span style="font-family: 宋体;">可能是基于云计算功能。国防工业基础网络保护计划（DCP2）中有一个重要选项，是将国防工业基础非密网络迁移到</span><span style="color: rgb(172, 57, 255);"><strong style="font-family: 宋体;">国防工业基础（DIB）云</strong></span><span style="font-family: 宋体;">，DIB公司可以使用这个云实现<strong>非密数据</strong>的计算和存储。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">如果实现了<strong>DIB云</strong>，DIB公司将获得的不仅仅是网络安全，还将免费获得<strong style="margin: 0px;padding: 0px;">计算和存储资源</strong>。DIB公司拥有的受控非密信息（CUI）将不再存储在本地，它将只在DIB云中存储和处理。</span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">云服务提供商（CSP）将为国防工业基础网络保护计划（DCP2）在商业云中划出一个</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;"><span style="font-size: 17px;margin: 0px;padding: 0px;font-family: 宋体;">安全飞地</span></strong></span><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-family: 宋体;">，并提供一组标准化的计算系统资源（CSR）</span></strong><span style="margin: 0px;padding: 0px;font-family: 宋体;">。国防工业基础网络保护计划（DCP2）将提供DIB云虚拟机和容器仓库，供DIB公司使用。云服务提供商（CSP）将负责修补和更新DIB成员公司使用的<strong>云基础设施</strong>。国防部还将建立和维护DIB云的<strong>元数据服务</strong>。</span></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;font-family: 宋体;font-size: 17px;">参与国防工业基础网络保护计划（DCP2）的DIB公司，将在<strong>自己的</strong><strong>安全飞地</strong>内得到一套标准化的安全计算系统资源（CSR）。<strong>不同公司的安全飞地相互隔离</strong>，并建立硬安全边界，以防止受控非密信息（CUI）和专有信息未经授权流动。而在DIB公司本地部署的网络由瘦客户端或胖客户端机器组成，它们被配置为防止公司数据的本地存储，不会将任何受控非密信息（CUI）存储在本地网络中。</span></section><section style="margin-top: 8px;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></section><section style="margin-top: 8px;">（本篇完<span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">）</span><br/></section><section style="margin-top: 8px;"><strong><span style="font-family: 宋体;">参考文献</span></strong><span style="font-family: 宋体;">：<span style="margin: 0px;padding: 0px;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: 宋体;color: rgb(0, 0, 0);">兰德公司</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: 宋体;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-weight: 400;">报</span></strong>告《<strong style="margin: 0px;padding: 0px;">非密安全：针对非密网络的国防工业基础网络保护计划</strong>》（</span><span lang="EN-US" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: Helvetica, sans-serif;">Unclassified and Secure - A Defense Industrial Base Cyber Protection Program for Unclassified Defense Networks</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: 宋体;">）的</span><strong>150页</strong><strong style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);font-family: 宋体;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">英文版原文</strong>下载地址：</span></section><section style="margin-top: 8px;"><span lang="EN-US" style=""><span style="font-family:宋体;"><a href="https://www.rand.org/pubs/research_reports/RR4227.html" target="_blank">https://www.rand.org/pubs/research_reports/RR4227.html</a></span></span></section>



<p><a href="2247494863">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a9f78c2c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494863%26idx%3D1%26sn%3Dfa7a0f699a289a1b99178c5d2e2e81bb%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 21 Aug 2022 12:51:00 +0800</pubDate>
    </item>
    <item>
      <title>云隔离的梦想</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494808&amp;idx=1&amp;sn=091baa50ba3e9bd4797ce7706511b59b</link>
      <description>我有一个梦想</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学 &amp;amp; 徐珊</span> <span>2022-08-14 06:36</span> <span style="display: inline-block;">北京</span>
</p>

<p>我有一个梦想</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=38301b23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTzQzibmq4VZ5JFEwbpvOt05ZKoWvFf1tD514VRDSFycPRcAoBLd3Sohg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">全文约<span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);"><strong style="margin: 0px;padding: 0px;">4000</strong></span>字  <span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);"><strong style="margin: 0px;padding: 0px;">10</strong></span>图表  阅读约<span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);"><strong style="margin: 0px;padding: 0px;">5</strong></span>分钟</p><section style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="margin: 0px;padding: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="margin: 0px;padding: 0px;max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="margin: 0px;padding: 0px 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;max-width: 100%;box-sizing: border-box;text-align: center;overflow-wrap: break-word !important;"><br style="margin: 0px;padding: 0px;"/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 0px;padding: 0px;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;padding: 0px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 0px;padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 0px;padding: 0px;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section style="text-align: left;">美国国防部把<span style="color: rgb(172, 57, 255);"><strong>隔离</strong></span>技术用到了极致：1）在涉密网和非密网之间使用<strong>网闸</strong><span style="color: rgb(61, 167, 66);"><strong>隔离</strong></span>；2）在非密网和互联网之间使用<strong>互联网</strong><span style="color: rgb(61, 167, 66);"><strong>隔离</strong></span>；3）在上云过程中使用<strong>云</strong><span style="color: rgb(61, 167, 66);"><strong>隔离</strong></span>；4）在数据中心使用<strong>微</strong><span style="color: rgb(61, 167, 66);"><strong>隔离</strong></span>。</section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;text-align: left;">总体来看，<strong>云是未来</strong>，<strong>浏览器是工作入口</strong>，所以云和浏览器隔离的结合，也就是<span style="color: rgb(172, 57, 255);"><strong>云隔离</strong></span>，可以实现<strong>隔离技术的</strong><span style="color: rgb(61, 167, 66);"><strong>普惠化</strong></span>，才可以把隔离的<span style="color: rgb(172, 57, 255);"><strong>梦想</strong></span>带到现实。<br/></section><section style="text-align: left;margin-top: 8px;">在安全领域，你可能不得不关注<strong>四大安全平台</strong>：1）网络安全领域中的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">SSE（安全服务边缘）</strong>平台；2）数据安全领域中的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">DSP（数据安全平台）</strong>；3）应用安全领域中的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">CNAPP（云原生应用保护平台）</strong>；4）事件响应领域的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">XDR（扩展检测与响应）</strong>。</section><section style="text-align: left;margin-top: 8px;">其中，<strong>SSE<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">（安全服务边缘）</strong>本质就是</strong><span style="color: rgb(172, 57, 255);"><strong>零信任云访问平台</strong></span>。<strong>Gartner将SSE作为四大安全平台之首</strong>，是有原因的。而<strong>每个SSE头部厂商都将</strong><span style="color: rgb(172, 57, 255);"><strong>云隔离</strong></span><strong>作为必备功能项</strong>，也是有原因的。本文将为你揭秘。</section><section style="text-align: left;margin-top: 8px;">聪明的读者会发现：本文与其说是<span style="color: rgb(172, 57, 255);"><strong>云隔离</strong></span>的梦想，不如说是<span style="color: rgb(172, 57, 255);"><strong>云访问</strong></span>的梦想，也就是<span style="color: rgb(172, 57, 255);"><strong>零信任云访问平台</strong></span><span style="color: rgb(0, 0, 0);"><strong>（<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">SSE</strong>）</strong></span>的梦想，终究也是<span style="color: rgb(172, 57, 255);"><strong>企业安全云</strong></span>的梦想。</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;text-align: left;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">本文来自</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">2022年8月2日<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">在</span></span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: justify;float: none;display: inline !important;">ISC </span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: justify;float: none;display: inline !important;">2022大会上的演讲《云隔离的梦想》，总共只有10张片子。<strong>视频</strong>见文末。</span></section></section></section></section></section></section><section style="margin: 15px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><span style="margin: 0px;padding: 0px;font-size: 20px;"><strong style="margin: 0px;padding: 0px;">目  录</strong></span><br style="margin: 0px;padding: 0px;"/></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">1.安全隔离的梦想<br/></p><p>2.何为云隔离平台</p><p>3.云隔离平台为何重要</p><p>4.美国国防部大力推进RBI项目</p><p>5.DISA技术路线图</p><p>6.成熟度曲线反映RBI日趋成熟</p><p>7.SSE前十厂商全部整合RBI能力</p><p>8.SSE的能力构成</p><p>9.RBI在正反两个方向同时工作，增强边缘安全方案</p><p>10.RBI与浏览器相得益彰</p><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></p><p><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">安全隔离的梦想</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><h1 style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.5608465608465608" style="font-size: 17px;text-align: justify;" data-type="png" data-w="945" src="https://wechat2rss.xlab.app/img-proxy/?k=c241615b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMGZsxfpzPRcrBeibQFvTkHYO6vic70rnB2VHRkaHSc2rVOicOic5eaS4McManuwHzJwI5GCTUfBz0iaUw%2F640%3Fwx_fmt%3Dpng"/></h1><section style="margin-top: 8px;">想必大家听说过美国黑人运动领袖马丁·路德·金发表的著名演讲——《I have a dream》（我有一个梦想），呼吁了<strong>种族平等</strong>。<br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">在安全行业里，也有一个梦想，是关于<strong>安全隔离</strong>的梦想——即把好的东西放进来，把坏的东西隔离在外。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">隔离的强度</span></strong><span style="font-size: 17px;">。值得提醒的是，<strong>隔离（Isolation）</strong>其实是一种非常强的安全控制措施，通常用于密级不同的网络之间，比如高密级和低密级之间。所以隔离经常会成为军方或涉密部门的强需求。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">谁是真隔离</span></strong><span style="font-size: 17px;">。真正敢称为“隔离”的产品和技术并不多。</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">有时候说的“隔离”，只是“分段”</span></strong><span style="font-size: 17px;">。<strong>隔离是Isolation；分段是Segment</strong>。比如说，<strong>微隔离=微分段</strong>（microsegment）。以前的网络安全域划分就是典型的“网络分段”，它是粗粒度的分段。在零信任的思想下，又产生了身份分段、应用分段、数据分段，这些算是细粒度的分段。但是，它们都不是隔离。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">最为人所熟知的隔离技术，是</span><strong><span style="font-size: 17px;">物理隔离</span></strong><span style="font-size: 17px;">。比如网闸、光闸这类安全设备。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">而<strong>虚拟化隔离</strong>呢？就要看他的操作系统底层，是否有足够强的隔离机制。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">那么，<strong>浏览器隔离</strong>呢？英文用的就是Isolation，所以它也算隔离。尽管浏览器隔离的强度不如物理隔离，但是浏览器隔离的使用场景比物理隔离广泛得多。这主要是因为<strong>浏览器已经成为工作入口</strong>。而且它还是很大的风口：比如，今年的RSA创新沙盒大赛冠军，就是<strong>Talon</strong>企业安全浏览器；而另一家成立不到两年的企业安全浏览器公司<strong>Island</strong>，估值竟高达13亿美元。实际上，经过全方位的对比，360企业安全浏览器是优于这两款国外企业安全浏览器了。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">这次的主题是<strong>云隔离</strong>：云隔离就是<strong>基于云的浏览器隔离</strong>。</span></section></li></ul><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">照亮隔离梦想</span></strong><span style="font-size: 17px;">。正因为<strong>云</strong>是未来，<strong>浏览器</strong>是工作入口，所以云和浏览器隔离的结合，也就是<strong>云隔离</strong>，就可以实现隔离技术的普惠化，也可以把隔离的梦想带到现实。</span></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">何为云隔离平台</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><h1 style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5608465608465608" style="font-size: 17px;" data-type="png" data-w="945" src="https://wechat2rss.xlab.app/img-proxy/?k=67189cb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricT6Eumy6EhkGzZFDqlKcqERFoZFoFDE3QfZYRHNb6yic4Kbg4uNSZSQkw%2F640%3Fwx_fmt%3Dpng"/><br/></h1><section style="margin-top: 8px;"><span style="font-size: 17px;">我们先解释云隔离是什么？然后再说明它为何重要。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">云隔离=云浏览器隔离=基于云的远程浏览器隔离</span></strong><span style="font-size: 17px;">。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">云隔离的基本思想：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">在<strong>用户浏览器</strong>和互联网网站之间，插入<strong>云端浏览器</strong>；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">用户浏览器想要访问的<strong>内容</strong>，由云端浏览器<strong>转发</strong>过来；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">用户浏览器本会遭受的<strong>威胁</strong>，都由云端浏览器来<strong>屏蔽</strong>掉。</span></section></li></ol><section style="margin-top: 8px;"><span style="font-size: 17px;">这里的关键是：<strong>怎么转发内容，怎么屏蔽威胁</strong>。也就是图中的第4步。这里存在三种技术路线：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">像素推送</span></strong><span style="font-size: 17px;">：云浏览器直接将网页展示的<strong>像素图像</strong>，传输给用户浏览器。这是非常安全的。</span></section></li><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">DOM重建</span></strong><span style="font-size: 17px;">：云浏览器通过<strong>重建网页的HTML和CSS等内容</strong>，来清除已知漏洞和潜在的恶意内容。</span></section></li><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">智能渲染</span></strong><span style="font-size: 17px;">：云浏览器向用户浏览器传输的内容是<strong>渲染指令</strong>，而非网页资源。</span></section></li></ol><section style="margin-top: 8px;"><span style="font-size: 17px;">这三种技术路线各有利弊，综合运用时，可以适用于不同安全等级的场景，从而发挥最佳效果。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">云隔离平台为何重要</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><h1 style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5576719576719577" style="font-size: 17px;" data-type="png" data-w="945" src="https://wechat2rss.xlab.app/img-proxy/?k=4acc8bbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTI5SYmfQqP1Q5bI2jJwerUCAYWWvlCotVe7BCP1z6ZuibSQ5xqw2wAVw%2F640%3Fwx_fmt%3Dpng"/><br/></h1><section style="margin-top: 8px;"><span style="font-size: 17px;">这里做了一个梳理，反映云隔离平台为何值得关注：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">美国<strong>国防部</strong>当前正在大力推进<strong>RBI项目</strong>。计划推广到它的几百万终端上。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">通过<strong>Gartner</strong>的成熟度曲线，来反映<strong>RBI技术日趋</strong><strong>成熟</strong>。</span></section></li><li><section style="margin-top: 8px;"><span style="color: rgb(172, 57, 255);"><strong><span style="font-size: 17px;">SSE（安全访问边缘）排名前十的国际供应商，全部整合了RBI能力</span></strong></span><span style="font-size: 17px;">。SSE是安全访问边缘，也就是零信任访问平台。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">RBI大大增强<strong>边缘安全</strong>解决方案。第3条只是一个外在现象，第4条却是内在本质。</span></section></li></ol><section style="margin-top: 8px;"><span style="font-size: 17px;">下面，分别解释下这几个方面。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">美国国防部大力推进RBI项目</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5619047619047619" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1a8fe299&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTaFOhW5Tcy3DA7ST1nkP5iazMuS61dUicuz51Owzrib1hqvXXj5LEM0hCA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">美国国防部的RBI项目名称是<strong>CBII</strong>（基于云的互联网隔离），本质就是基于云的远程浏览器隔离。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">美国国防部采用RBI的一个非常重要的原因，就是他们发现，针对美国国防部网络的攻击中，大约有<strong>30%到70%来自浏览器</strong>。所以，<strong>浏览器成为最大的攻击暴露面</strong>。而RBI技术就可以解决此问题。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">DISA开展RBI项目的大概过程是这样的：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">2018年6月，DISA（国防信息系统局）发布RBI方案需求；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">2020年8月，DISA以<strong>1.99亿美元</strong>，签订RBI项目合同。<strong>Menlo</strong> Security公司负责CBII项目解决方案的交付工作。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">2020年底，DISA（国防信息系统局）发布《2019-2022财年战略计划》2.0版本。将RBI纳入未来两年的<strong>战略计划</strong>。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">2021年初，CBII技术已经完成<strong>测试验证</strong>，处于国防部内部推广部署的阶段。DISA原计划在2021财年将其扩展到<strong>整个国防部</strong>，并将其应用于电子邮件和附件。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">2021-2022年期间，DISA计划大力推进RBI项目的部署实施，将其扩展到整个国防部，将RBI用户数量从最初的10万，最终扩展至<strong>350万</strong>。DoD总共有多少人呢？不过两三百万（美军现役加文职大概200万）</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">接下来，再看看DISA战略计划中的RBI内容。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">DISA技术路线图</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5619047619047619" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5428d5f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTpibL06JBibZyELMzIylGB7bYgH3xMoPYu51mYibQNzmOhW073fNGuaic1A%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">在DISA的《2021-2022财年战略计划》图中，我们用以红色字体标记了RBI项目。其中，这个技术路线图中，有<strong>三大领域：网络防御、云计算、企业办公</strong>。而RBI项目，则同时出现在网络防御和云计算这两个领域中。我们分别来看看：</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">在<strong>网络防御</strong>领域，DoD有三层纵深防御：边界防御+区域防御+终端防御；而云隔离属于边界防御的范畴。我来解释一下：美国国防部有<strong>涉密网</strong>和<strong>非密网</strong>两类网络，会产生两种连接需求：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">一是<strong>涉密网和非密网</strong>的连接，采取类似<strong>物理隔离</strong>（也就是网闸、光闸）的方法来解决；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">二是<strong>非密网和互联网</strong>的连接，以前主要使用老三样（也就是防火墙、防病毒、入侵检测），当然还有安全大脑的分析。但它现在有了<strong>RBI</strong>以后，就可以极大减少面向互联网的暴露面。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">在<strong>云计算领域</strong>有3项关键工作（右下角浅蓝色框）：一是云基础设施（<strong>云连接</strong>）；二是云访问和安全（<strong>云访问</strong>）；三是基于云的互联网隔离（CBII）（<strong>云隔离</strong>）。正是通过这<strong>三个大招（云连接、云访问、云隔离）</strong>，DoD搞定了安全上云问题。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">现在，我来总结一下：1）DoD在涉密网和非密网之间使用<strong>网闸隔离</strong>；2）在非密网和互联网之间使用RBI，被称为“<strong>互联网隔离</strong>”；3）在国防部的云中，也使用了RBI，被称为“<strong>云隔离</strong>”；4）在数据中心中，则使用零信任的<strong>微隔离</strong>。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">所以，我才认为，<strong>美国国防部把隔离技术用到了极致，也几乎实现了隔离梦想的普惠化</strong>。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">成熟度曲线反映RBI日趋成熟</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5576719576719577" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=f2bb113b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTJPHHXr1JNy3s849F4qGZfdFvV3tn76Ddoz9Bo102icZg3sicibt327RWg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">Gartner是顶级的咨询机构，其成熟度曲线非常著名。但其实它来自心理学领域著名的<strong>达克效应</strong>，反映了人类认知事物的过程，主要包括3段：<strong>愚昧之山+绝望之谷+开悟之坡</strong>：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">人们总是先兴冲冲地登上<strong>愚昧之山</strong>（就像说风口来了、风口来了，跟着炒概念）；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">然后发现现实没有想象的那么美好，于是跌下神坛，掉入<strong>绝望之谷</strong>；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">历经过度的<strong>希望</strong>和过度的<strong>失望</strong>之后，终于产生了稳定的<strong>期望</strong>。于是踏上了<strong>开悟之坡</strong>。</span></section></li></ol><section style="margin-top: 8px;"><span style="font-size: 17px;">2017年，浏览器隔离（BI）技术被纳入Gartner 11大顶级安全技术。2018年进入Gartner端点安全和网络安全这两条成熟度曲线。我们对比了近5年的成熟度曲线，发现BI/RBI依次经过上升期、山顶期、低谷期，已经逐步趋于成熟。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">07</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">SSE前十厂商全部整合RBI能力</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.562962962962963" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=54ac069a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTWnt1eDeSfvIPMk1ghX14j61jUHVX1uAQicKt93E8iajvdRWrwPD6HdCQ%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">正是因为RBI在技术上基本成熟，所以相关的国外供应商，开始加速整合RBI能力。在Gartner于2022年2月发布的《安全服务边缘（SSE）魔力象限》，象限中的<strong>所有提供商</strong>，看起来是11个，但因为有收购关系，正好是10个。我逐个排查了一遍，发现他们全部都整合了RBI能力，当然有各种整合方式，有自研、有收购、有集成、有合作等。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">当然了，这只是一个表象和结果。我们会问，<strong>原因是什么？</strong>只是因为RBI技术成熟了吗？非也。下面进行解读。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">08</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">SSE（安全服务边缘）的能力构成</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5587301587301587" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=28f08129&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTibdAAcTKJPkCT12Wmnp72gSST7kgY3LdFNUjSlk4NmO4h2E0L3ialbzA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">四大安全平台</span></strong><span style="font-size: 17px;">。在安全领域，你可能不得不关注四大平台：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">SSE（安全服务边缘）</span></strong><span style="font-size: 17px;">：<strong>边缘零信任</strong>访问平台。</span></section></li><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">DSP（数据安全平台）</span></strong><span style="font-size: 17px;">：统合<strong>数据安全控制</strong>，逐步淘汰孤立的数据安全工具。</span></section></li><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">CNAPP（云原生应用保护平台）</span></strong><span style="font-size: 17px;">：涵盖<strong>云原生应用程序</strong>的整个生命周期（从开发到生产的闭环）。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;"><strong>XDR（扩展检测与响应）</strong>：面向威胁检测与响应，降低安全运营复杂性。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">Gartner把SSE列为四大平台之首，可见对SSE的重视。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">SASE背景</span></strong><span style="font-size: 17px;">。我们知道，自Forrester提出来的零信任架构大火之后，Gartner也不甘示弱，在2019年提出SASE（安全访问服务边缘）架构。SASE架构的愿望非常好，融合了网络+安全两个方面，形成一体化安全架构。然而，理想很丰满，现实很骨感。当前大多数大型组织，都有<strong>独立的网络团队和安全团队</strong>，他们通常做出互相独立的采购决策，难以有效整合网络和安全这两个方面的工作。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">SSE概念</span></strong><span style="font-size: 17px;">。于是，Gartner于2021年又提出SSE新概念，SSE由SASE缩减而来，SSE是从SASE中解耦出来的纯安全部分，<strong>更加容易落地</strong>。本质就是想把<strong>安全与网络解耦</strong>。所以，这是一个很有意思的现象：<strong>SASE用来融合网络和安全；而SSE则用来解耦网络和安全</strong>。当然，从某种程度上看，这是对现实的妥协，也算是对企业客户的尊重。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">在甩掉网络的包袱后，<strong>Gartner对SSE寄予厚望</strong>。除了把SSE列为四大平台之首，还把SSE纳入Gartner的<strong>4条成熟度曲线</strong>：云安全、端点安全、网络安全、应用安全。你觉得4条不够多是吧？Gartner的成熟度曲线的确很多，但是跟咱们安全密切相关的成熟度曲线，总共也就7条（还有身份与访问管理（IAM）、数据安全、安全运营）。</span></section><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">为什么SSE架构要集成RBI能力？</span></strong><span style="font-size: 17px;">如上图所示：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">SSE是以<strong>零信任</strong>为基础的，这是底层能力；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">SSE对外体现为<strong>3大网关能力</strong>，也是<strong>3大支柱能力</strong>：SWG（安全Web网关）、CASB（云访问安全代理）、ZTNA（零信任网络访问，即SDP）。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">而在中间层的<strong>安全服务</strong>能力中，RBI为什么能占有一席之地？因为它能够<strong>同时补充和增强这3大网关能力</strong>。下面来解释为什么这么说？</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">09</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">RBI在正反两个方向同时工作，增强边缘安全方案</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5597883597883598" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=80325ba1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTomFQxr9HYry7ibozxCFcZEQEh0oib3cybjdjicHXQY2BXngI6sFnwYluw%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">在这里，我们看到了前面SSE平台的<strong>三种网关</strong>：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">SWG（安全Web网关）：保护用户终端，免受互联网Web攻击。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">SDP（零信任网关）：保护云中<strong>私有应用</strong>，免遭网络攻击。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">CASB（云访问安全代理）：保护<strong>SaaS应用</strong>，免遭数据泄露。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">而RBI有正反两种工作方式，大家比较熟悉的是正向方式。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;">RBI在<strong>正向工作</strong>时：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">可以<strong>保护用户终端</strong>，免受互联网Web攻击。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">而这种场景正是<strong>SWG</strong>（安全Web网关）的核心价值。</span></section></li><li><section style="margin-top: 8px;"><strong><span style="font-size: 17px;">差异性</span></strong><span style="font-size: 17px;">：SWG仅针对<strong>已知威胁</strong>，例如白名单网站或者黑名单网站；而RBI则可以应对<strong>未知风险网站</strong>。两者组合才能高效防护。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">RBI在<strong>反向工作</strong>时：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">可以<strong>保护企业敏感数据和应用</strong>，免遭数据泄露。注意：它不是防止终端上的数据泄露，而是防止云中企业数据的泄露。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">而<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">这种场景</span>正是零信任<strong>SDP</strong>网关（保护私有应用）和<strong>CASB</strong>（云访问安全代理，保护SaaS应用）的核心价值。</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;"><strong>差异性</strong>：有了RBI之后，应用程序（私有应用或SaaS应用）返回的数据，不会直接传给用户终端，而是传给云隔离平台。也就是说<strong>数据可以不落地</strong>，用户终端拿不走敏感数据（包含文件、邮件等）。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">所以，综合上述正反两种工作方式，RBI可以极大地补充和增强SSE的三大支柱能力。这才是RBI真正的<strong>价值</strong>所在。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">10</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">RBI与浏览器相得益彰</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></section><section style="margin-top: 8px;"><img class="rich_pages wxw-img" data-ratio="0.5544973544973545" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1572209e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMW5Ztup8UArgBE0ohZZricTJc9RJOY44fN2wPR3ZokQQNiaLwkicvfe0AjZXcyDaSx37xiaGhG8Ggw2A%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 8px;"><span style="font-size: 17px;">最后，再强调下：<strong>RBI与浏览器是相辅相成、相得益彰的</strong>：</span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><span style="font-size: 17px;">一方面，RBI保护了客户浏览器，避免了客户浏览器的失陷；</span></section></li><li><section style="margin-top: 8px;"><span style="font-size: 17px;">另一方面，RBI中<strong>云端浏览器毕竟也是浏览器</strong>。只有对浏览器技术的深入理解，才能造就出强大的RBI产品。</span></section></li></ul><section style="margin-top: 8px;"><span style="font-size: 17px;">所以，360企业安全浏览器与360云隔离平台的结合，是一种强强联合。可以为云隔离梦想的实现，贡献力量。</span></section><section style="margin-top: 8px;"><span style="font-size: 17px;"><br/></span></section><section style="margin-top: 8px;"><span style="color: rgb(34, 34, 34);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 2px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">（本篇完）</span></section><section class="channels_iframe_wrp"><mpvideosnap class="js_uneditable custom_select_card channels_iframe videosnap_video_iframe" data-pluginname="videosnap" data-id="export/UzFfAgtgekIEAQAAAAAAxk8nXDut6AAAAAstQy6ubaLX4KHWvLEZgBPE0qAMaHsLfv2CzNPgMIvcQBpZCpBMZ79__sUEFzuQ" data-url="https://findermp.video.qq.com/251/20350/stodownload?encfilekey=okgXGMsUNLEibHKtCw1bRNicxw6C1zsevQ9TxKoFqWL6aic7xqdvcq7JicBnlRpUOxTAKDOAEM8C1Ha1yCn0Cpsr4ImPuib0RNjia3TFRWKDMibwTYV44KSk9iaUYzu1RibhIXUoZDEpzAf6NjfOWODIGneYW3u51FQabUXgb&amp;adaptivelytrans=0&amp;bizid=1023&amp;dotrans=0&amp;hy=SH&amp;idx=1&amp;m=c2d11a8c50f643f1557ae284f254ad27&amp;token=AxricY7RBHdVmD4Af6MecDhCJRLxXkRx53UO64dOrT6zWbfkVCLwvHcjtl6EiaBesjSjh1XSZnRVo" data-headimgurl="http://wx.qlogo.cn/finderhead/Q3auHgzwzM6rb3NeWQPNsMekakAXASZicYbCXtHibkaic9Vc8ErxD7TKg/0" data-username="v2_060000231003b20faec8c6e5811fc4d7cb00e53cb077a0cefa93e0080ac3cca05b221fbbb911@finder" data-nickname="音乐有光" data-desc="2022年8月2日，在2022年ISC（互联网安全大会）上所做演讲《云隔离的梦想》。在安全领域，可能不得不关注四大安全平台：SSE（安全服务边缘）+DSP（数据安全平台）+CNAPP（云原生应用保护平台）+XDR（扩展检测与响应）。其中，SSE本质就是零信任访问平台。Gartner将SSE作为四大安全平台之首，是有原因的。而每个SSE头部厂商都将云隔离作为必选项，也是有原因的。这个演讲将为你揭秘。" data-nonceid="14975487510508933274" data-type="video" data-width="1920" data-height="1080"></mpvideosnap></section><section style="margin-top: 8px;"><span style="color: rgb(34, 34, 34);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 2px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></section>



<p><a href="2247494808">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=14180449&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494808%26idx%3D1%26sn%3D091baa50ba3e9bd4797ce7706511b59b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 14 Aug 2022 06:36:00 +0800</pubDate>
    </item>
    <item>
      <title>美国国防部的百亿大单和上云启示</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494806&amp;idx=1&amp;sn=7bd42a96f6448127b2adcdb00cb1afba</link>
      <description>金山银山，皆在云中</description>
      <content:encoded><![CDATA[<p>
原创 <span>一帆 &amp;amp; 柯学</span> <span>2022-08-07 06:53</span> <span style="display: inline-block;">北京</span>
</p>

<p>金山银山，皆在云中</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=59ebce10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNeBMJic3PN1ibg8m1rRW9fjhThJRZpCP83MBUMcIkNgpNU0OhT0p21qnQXwmtrzaj4xz9z0QnIyEqw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>4000</strong></span>字  阅读约<span style="color: rgb(0, 0, 0);"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t"><section style="text-align: left;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">美国国防部有</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(61, 167, 66);display: inline !important;"><strong>两个</strong></span><strong><span style="color: rgb(172, 57, 255);">百亿美元</span></strong><strong><span style="color: rgb(61, 167, 66);">云计算合同</span></strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">——<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">国防飞地服务</strong></span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">（DES）</strong>和</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">联合作战云能力（JWCC）</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">计划：</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);"></span></strong></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">DES参考：《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493985&amp;idx=1&amp;sn=2e06682adae40ae94da87b218e32d683&amp;chksm=97fa3407a08dbd111398b8a0a9b1a59cf2ebde72638f824907b15d927e471c7655225b8c36b6&amp;scene=21#wechat_redirect" textvalue="美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;" data-linktype="2"><span style="margin: 0px;padding: 0px;color: rgb(0, 82, 255);text-decoration: underline;">美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）</span></a>》<br style="margin: 0px;padding: 0px;"/></section></li><li><section style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">JWCC参考：《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494461&amp;idx=1&amp;sn=d8228f9d95bc4f1bc73a5851a2d44981&amp;chksm=97fa365ba08dbf4d6185dbd29b572864714a9de9c748852b3b69c6e2abf9cbabb61e4c66bc51&amp;scene=21#wechat_redirect" textvalue="绝地云上的绝地反击" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;" data-linktype="2"><span style="margin: 0px;padding: 0px;color: rgb(0, 82, 255);text-decoration: underline;">绝地云上的绝地反击</span></a>》</section></li></ul><section style="text-align: left;margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);">本文意在更新这两个大单的进展：<br/></span></strong></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-align: left;margin-top: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">国防飞地服务</span>（DES）项目合同已授予<strong>Leidos公司</strong>；</p></li><li><p style="text-align: left;margin-top: 0px;">联合作战云能力（JWCC）项目合同授予将<strong>推迟到2022年12月</strong>。</p></li></ul><section style="text-align: left;margin-top: 8px;">本文还将通过一名<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">技术顾问在</span><strong>Dragon Cloud（龙云）</strong>推进过程中的<strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">心路历程</span></strong>，来体会<span style="color: rgb(172, 57, 255);"><strong>美军如何突破上云的阻碍</strong></span>：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="text-align: left;margin-top: 0px;">最艰难的因素是推动一种<strong>更具风险承受能力</strong>的<strong>云文化</strong>；</p></li><li><p style="text-align: left;"><strong><span style="color: rgb(0, 0, 0);"><span style="color: rgb(0, 0, 0);margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;">通常是</span></span></strong><strong>高层领导</strong><span style="color: rgb(0, 0, 0);">在早期犹豫不决；</span><strong><span style="color: rgb(0, 0, 0);"></span></strong></p></li><li><p style="text-align: left;margin-top: 0px;"><strong><span style="color: rgb(0, 0, 0);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">通过</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">技术演示</strong></span></strong><span style="color: rgb(0, 0, 0);">打开高层领导的想象空间；<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></span></p></li><li><p style="text-align: left;margin-top: 0px;"><span style="color: rgb(0, 0, 0);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">从<strong>非密</strong>云资源扩展到<strong>涉密</strong>云资源。</span></span><strong><span style="color: rgb(0, 0, 0);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></span><span style="color: rgb(0, 0, 0);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></span><span style="color: rgb(0, 0, 0);"></span></strong><span style="color: rgb(0, 0, 0);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"></strong></p></li></ul><section style="text-align: left;margin-top: 8px;">面对许多<strong>不敢联网</strong>、<strong>不敢上云</strong>的行业和领导，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">这<strong>4</strong><strong>个洞察</strong>或许戳中了痛点！</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></section></section></section></section></section></section><p style="text-align: left;margin-top: 8px;"><span style="font-size: 20px;"><strong><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;">关键词</span></strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">：<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">DES</strong><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">（</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">国防飞地服务</strong><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">，Defence Enclave Services）；</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;">JWCC</span></strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;text-align: left;">（<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">联合作战云能力</strong>，Joint Warfighting Cloud Capability）</span>；</span></strong><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">JEDI</strong>（<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">绝地</strong>/联合企业防御基础设施，Joint Enterprise Defense Infrastructure）；<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">JADC2</strong>（<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;text-align: left;">联合全域</span>指挥与控制</strong>，Joint All-Domain Command and Control）；</span></strong></span><strong>GAO</strong><span style="font-size: 20px;"><strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline !important;">（</span></strong></strong></span></strong></span><span style="font-size: 20px;"><strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline !important;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">政府问责</strong></span></strong></span><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 20px;color: rgb(0, 0, 0);"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;">局</strong></span></strong></span>，Government Accountability Office<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;display: inline !important;">）；</span></strong></strong></span></strong></span></strong></span></p><section style="text-align: center;margin-top: 15px;margin-bottom: 0px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;">1.<strong style="margin: 0px;padding: 0px;">美军上云的启示</strong></p><p style="margin-bottom: 0px;">2.<strong>DES</strong>合同被授予Leidos<strong style="max-width: 100%;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"></span><strong style="max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="max-width: 100%;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></span></strong></span></strong></strong></strong></strong></p><p style="margin-bottom: 0px;">3.<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">JWCC</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">合同被</span>延迟授予<br/></p><p>4.美军的其它云项目</p><p><br/></p><p style="text-align: left;margin-bottom: 0px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 2px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">美军上云的启示</strong></span></strong></span></strong></strong></strong></strong></strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 10px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;"/></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><img class="rich_pages wxw-img" data-ratio="0.5611111111111111" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2640762a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPsdia2O4G1wbSP8NDZUuJ4aP12x7wujQgYiaiacSakCArbib1pAv3iaZhAg8tffQibeDPbXxByMc3vn1Tg%2F640%3Fwx_fmt%3Dpng%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></strong></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">图1-国防部企业云战略<br/></strong></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">不论<strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">IT</strong>还是安全，美国国防部都在尽可能地对可以</strong><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(122, 79, 214);"><strong style="margin: 0px;padding: 0px;">通用化</strong></span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">的产品和服务进行</strong><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(122, 79, 214);"><strong style="margin: 0px;padding: 0px;">标准化</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">以避免各行其是的</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">定制化</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">归根结底是两字诀：一是“<strong style="margin: 0px;padding: 0px;">快</strong>”（快速应用和创新），二是“<strong style="margin: 0px;padding: 0px;">省</strong>”（省钱）。</span></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;"><span style="color: rgb(0, 0, 0);"><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">比如两个</span><span style="margin: 0px;padding: 0px;">百亿美元</span><span style="margin: 0px;padding: 0px;">云计算合同</span></span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">，即</span>联合作战云能力（JWCC）<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">和国防飞地服务</span>（DES）<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">计划，都是通用化和标准化的上云项目。</span></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">但这并不意味着美国人天生就容易接受新理念、新技术。实际上，<strong>美军在其上云之路上也是经历了百转千回</strong>。</p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">美军<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">第十八空降兵团第</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">101空降师高级技术顾问布赖恩·麦克唐纳 (Brian <strong>McDonell</strong>)就对此深有感触。通过他讲述的故事，我们也可以感受到美军上云的心路历程。</span><span style="text-align: justify;"></span></p><p style="margin-top: 8px;"><strong>1）推动风险承受度</strong>。McDonell参与了<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">应急部队的</span><strong>Dragon Cloud</strong><strong>（</strong><strong>龙云）</strong>（参见后文）的建设，他表示，<strong>上云推进工作中最艰难的因素之一是</strong><strong>推动一种</strong><span style="color: rgb(172, 57, 255);"><strong>更具风险承受能力</strong></span><span style="color: rgb(172, 57, 255);"><strong>的文化</strong></span><strong>，以便进行更深入的实验</strong>。</p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong>2）高层领导是障碍</strong>。他说：“我们提前把云环境全部建成，还进行了为期一个月的现场演练，准备出去使用所有这些云的东西。这时，有<span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">一群指挥官说“我不想使用它”</strong></span>，因为他们很害怕。没有人相信它，这是<span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">有史以来第一次</strong></span>。<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">”</span><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(0, 0, 0);display: inline !important;">高层领导</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">在早期的犹豫不决，是非常普遍的现象。</span><br style="margin: 0px;padding: 0px;"/></section><p style="margin-top: 8px;"><strong>3）说服和技术演示</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。McDonell</span>表示，要想获得相关领导的支持，<strong>最</strong><strong>致命的一击</strong>就是<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">在说服他们值得冒险之后，</span>通过<span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">技术演示</strong></span>向他们展示好处。</p><p style="margin-top: 8px;"><strong>4）</strong><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><strong>尝试非密云资源</strong>。McDonell</span>说：</span>“我在布拉格堡（<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">Fort Bragg</span>）遇到一位<strong>三星级将军</strong>，他的陆军配发电脑是他的<strong style="margin: 0px;padding: 0px;">非密电脑</strong>。我给了他一个URL，他点击了我从肯塔基州坎贝尔堡（Fort Campbell, Kentucky）部署、配置、维护的<strong style="margin: 0px;padding: 0px;">云资源</strong>——<strong>他立刻就</strong><span style="color: rgb(172, 57, 255);"><strong>被震撼</strong></span><strong>到了</strong>。<strong>而这正是最欣喜若狂的事</strong>。之后，我们开始探索其他机会。我们开始尝试与欧洲的部队建立联系，而所有的<strong>云尝试都开始</strong><span style="color: rgb(172, 57, 255);"><strong>迅速蔓延</strong></span>。”</p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong>5）拓展涉密云资源。</strong>正是从那里开始，<strong>官员们选择进一步扩展云功能</strong>，以托管与任务指挥系统相关的<span style="color: rgb(172, 57, 255);"><strong>敏感和<strong style="margin: 0px;padding: 0px;">涉密</strong>工作负载</strong></span>，并使它们能够在<strong>全球可访问的云环境</strong>中运行。“所以我将我在坎贝尔堡的目标系统，连接到并共享复制到<strong>德国本地</strong>目标系统的数据。<strong>它是实时的，没有延迟</strong>。太棒了！”McDonell说。“而且我们今天仍在这样做。我们现在仍在添加各种服务，以构建这种云环境。”</section><p style="margin-top: 8px;"><strong>6）</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><strong>以</strong><strong>云改进</strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">SWaP指标</strong>。McDonell</span>补充说，服务需要到达一个士兵可以<strong style="margin: 0px;padding: 0px;">停止背负网络</strong>的地方。而<strong>基于云的应用程序，就有助于减轻所有硬件繁重的负担</strong>。“<strong>SWaP（大小、重量、功率<span style="font-weight: 400;">）</span></strong>是我们通常用来评估选项可行性的一个指标。<strong>我们一直在努力减少大小、重量并提高功率</strong><strong>，以使我们更加敏捷、更具杀伤力和战斗力</strong>。通过在这种混合环境中使用云——我说混合是因为我们总是会为那个战士在战术边缘配备某种硬件——但是在将其他所有东西都托管在云中时，我们可以提升<strong><span style="font-weight: 400;">SWaP中</span>60%的改进</strong>。”他说。</p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">随着这项工作的继续展开，相关人员正在认真考虑确保云环境可以在全球范围内使用，并最终对整个陆军和国防部产生持久影响。</section><section style="margin: 16px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">DES被授予Leidos</strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 8px 0px 10px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">DES的详细情况请参考《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493985&amp;idx=1&amp;sn=2e06682adae40ae94da87b218e32d683&amp;chksm=97fa3407a08dbd111398b8a0a9b1a59cf2ebde72638f824907b15d927e471c7655225b8c36b6&amp;scene=21#wechat_redirect" textvalue="美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;"><span style="margin: 0px;padding: 0px;color: rgb(0, 82, 255);text-decoration: underline;">美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）</span></a>》。</p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">DES（<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">国防飞地服务</span>）是美国国防部推动<strong style="margin: 0px;padding: 0px;">数字化转型</strong>的重要举措，被誉为<strong style="margin: 0px;padding: 0px;">国防部IT改革的皇冠上的宝石之一</strong>。其核心工作内容是<span style="margin: 0px;padding: 0px;color: rgb(122, 79, 214);"><strong style="margin: 0px;padding: 0px;">通用IT</strong></span><strong style="margin: 0px;padding: 0px;">的整合</strong>和<span style="margin: 0px;padding: 0px;color: rgb(122, 79, 214);"><strong style="margin: 0px;padding: 0px;">安全性</strong></span><strong style="margin: 0px;padding: 0px;">的提升</strong>。</p><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">作为庞大的<strong style="margin: 0px;padding: 0px;">云计算合同</strong>，DES的目的是改变国防部“<strong style="margin: 0px;padding: 0px;">第四产业</strong>”<span style="margin: 0px;padding: 0px;text-align: left;">（Fourth Estate）</span>的<strong style="margin: 0px;padding: 0px;">IT运营</strong>状况（含安全运营），<span style="margin: 0px;padding: 0px;text-align: left;">旨在通过企业电子邮件、语音、视频、协作和更好的网络安全性，来</span>解决<strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">第四产业IT生态系统效率低下</strong>的问题。所谓“<span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">第四产业</strong></span>”，<span style="margin: 0px;padding: 0px;text-align: left;">主要是指国防部内<strong style="margin: 0px;padding: 0px;">除了军种和情报机构之外</strong>的<strong style="margin: 0px;padding: 0px;">国防机构和外勤机构（DAFA）</strong></span>。</p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">2019年，国防部副部长指定<strong style="margin: 0px;padding: 0px;">DISA作为单一服务提供商</strong>，以优化其<strong style="margin: 0px;padding: 0px;">22个</strong>第四<span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);">产业机构</span>的网络能力。<br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;">2022年3月10日，</strong>DISA在其官网宣布：<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">将DES（国防飞地服务）合同授予</span>弗吉尼亚州雷斯顿的<strong style="margin: 0px;padding: 0px;">Leidos公司</strong>。<br style="margin: 0px;padding: 0px;"/></section><section style="margin: 8px 0px 0px;padding: 0px;">DES合同的最高价值为<span style="color: rgb(172, 57, 255);"><strong>115亿美元</strong></span>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">这是一份单一授予的无限期交付/无限量合同，</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">有1个为期4年的基本履约期，随后是3个为期2年的选择期。</span>合同期自<span style="color: rgb(172, 57, 255);"><strong>2022年2月28日</strong></span><strong>开始。</strong>招标还要求所有要约人<strong style="margin: 0px;padding: 0px;">将至少25%的工作分包给小企业</strong>。Leidos的提案超过了这个最低限度。</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">DES合同涉及为超过<span style="margin: 0px;padding: 0px;color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">37万</strong></span>名用户提供广泛的IT服务，这些用户跨越<strong style="margin: 0px;padding: 0px;">22个</strong>国防机构和在美国和国外拥有<strong>500多个站点</strong>的外勤机构。<span style="margin: 0px;padding: 0px;text-align: center;"></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">作为DES承包商，在<strong>DISA的第四产业网络优化计划办公室</strong>的指导下，<strong>Leidos</strong>将管理和运营网络架构，并提供必要的技术专业知识，以提供标准化、响应迅速、具有成本效益的IT服务，专注于任务价值和网络用户体验，同时<strong>提高第四产业机构的安全性、网络可用性、可靠性</strong>。<br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3896535358329378" data-s="300,640" style="text-align: center;" data-type="png" data-w="2107" src="https://wechat2rss.xlab.app/img-proxy/?k=1885adf6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNgrgISJCDPHEzMoomhWXIxkhPaIQPHfkuuAwK0GySLMYVtEvpTS0Ap1XM00em2zK4DWibTU4wJkog%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="text-align: center;margin-top: 8px;"><strong>图2-DES的工作内容</strong><span style="color: rgb(51, 51, 51);margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"></span></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong>Leidos公司简介</strong>。Leidos（纽约证券交易所代码：LDOS）是财富500强中技术、工程、科学解决方案和服务的领导者，致力于解决<strong>国防、情报、民用、卫生</strong>市场中世界上最严峻的挑战。Leidos 的<strong>4.3万名员工</strong>为政府和商业客户的重要任务提供支持。Leidos总部位于美国弗吉尼亚州雷斯顿，截至2021年12月31日的财政年度的年收入约为<strong>137亿美元</strong>。</section><section style="margin-top: 8px;"><strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Leidos</strong>中标之波折</strong>。2022年<strong>2月</strong>28日，Leidos就在其官网上宣布获得了DISA授予的国防飞地服务 (DES) 合同。称其为该<strong>公司历史上金额最大的合同</strong>。然而，<strong>3月</strong>10日，<strong><span style="font-weight: 400;">GDIT</span></strong> (通用动力信息技术) 向<strong>政府问责</strong><span style="color: rgb(0, 0, 0);"><strong>局</strong></span>(GAO) 提出了投标抗议，导致政府问责<span style="color:#ff0000;"><span style="color: rgb(0, 0, 0);">局</span></span>对此项投标进行审查。直到<strong>6月</strong>22日，Leidos再次在其官网上宣布：DES合同经由政府问责<span style="color:#ff0000;"><span style="color: rgb(0, 0, 0);">局</span></span>彻底的审查之后，得到确认和维持。</section><section style="margin-top: 8px;">然而，在后文的<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">空军Cloud One项目</strong>中，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">Leidos就比较悲剧了。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">Leidos在2016年中标了Cloud One项目，却在2020年<strong>被解</strong><strong>雇</strong>！</span></span></section><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></section><section>Leidos官网上的几个<strong>其它</strong><strong>军方大单</strong>：<br/></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><strong>海军海上系统司令部后续合同</strong>：2022年7月，获得了一份后续合同，以支持海军项目执行办公室综合作战系统指挥部。单项授予的成本加固定费用合同价值约为<strong>2.91亿美元</strong>。它包括一年的基本期和四个额外的一年选择期。工作将在全球范围内进行。</p></li><li><p><strong>北约弹道导弹防御合同</strong>：2022年5月，获得北约通信和信息局（NCI Agency）授予的两项国际竞争合同，以增强联盟的弹道能力导弹防御（BMD）能力。两份单一授予的固定价格合同的总估计价值为<strong>9000万美元</strong>，每份合同的履约基期为四年，最多可有四个选择期。</p></li><li><p><strong>美国海军海底战争系统合同</strong>：<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">2022</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">年</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">3</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">月</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">获得美国海军</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">海军</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">信息战</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">系统司令部</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"> (NAVWAR)</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"> 授予的主要合同，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">以支持</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">该</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">军种</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">的</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">海底战系统</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">这个单一奖项</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">的</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">下一代海港 (NxG) </strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">任务订单的总估计价值为</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">8400万美元</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">它包括一年的基期，</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">以及四个一年的选择期。</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">工作将在弗吉尼亚州和日本进行</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span></p></li></ul><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">JWCC合同被延迟授予 </strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin: 10px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: left;">JWCC的详细情况请参考《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494461&amp;idx=1&amp;sn=d8228f9d95bc4f1bc73a5851a2d44981&amp;chksm=97fa365ba08dbf4d6185dbd29b572864714a9de9c748852b3b69c6e2abf9cbabb61e4c66bc51&amp;scene=21#wechat_redirect" textvalue="绝地云上的绝地反击" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="margin: 0px;padding: 0px;color: rgb(87, 107, 149);text-decoration: none;"><span style="margin: 0px;padding: 0px;color: rgb(0, 82, 255);text-decoration: underline;">绝地云上的绝地反击</span></a>》。</p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">JWCC项目旨在</span>打造一项<strong style="margin: 0px;padding: 0px;">多云</strong>工作，将为国防部提供<strong style="margin: 0px;padding: 0px;">所有三个安全级别的企业云能力</strong>：<strong style="margin: 0px;padding: 0px;">非涉密、机密、绝密</strong>，从<strong style="margin: 0px;padding: 0px;">美国大陆</strong>一直到<strong style="margin: 0px;padding: 0px;">战术边缘</strong>。JWCC将为<strong style="margin: 0px;padding: 0px;">JADC2</strong>（联合全域指挥和控制）计划提供服务，并协助人工智能应用等。  </section><p style="margin-top: 8px;">2021年7月，国防部官员预计采购合同将在<strong>2022年4月</strong>准备就绪。当时<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">预计只有</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">两家</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">云服务提供商有资格竞标采购。</span> 但是<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">国防部</span>在进行市场调查后，于2021年11月，将五家公司纳入考虑，最终<strong>四家</strong>收到了招标，即<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">谷歌、甲骨文、微软、AWS</span>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">云服务提供商的数量</span><strong>从两家增加到四家，极大地复杂了评估周期</strong>。</p><p style="margin-top: 8px;">于是，<strong>2022年3月31日</strong>，国防部网站发布消息称，国防部首席信息官John Sherman（约翰·谢尔曼）表示，<strong>计划在</strong><span style="color: rgb(172, 57, 255);"><strong>2022年12月</strong></span><span style="color: rgb(172, 57, 255);"><strong>授予JWCC</strong></span><strong>（联合作战云能力）<span style="font-weight: 400;">采购合同，</span></strong>以便有更多时间来评估供应商的提案。 </p><section style="margin: 8px 0px 0px;padding: 0px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">谢尔曼表示，</span>更改为12月授予合同，并不表明采购有任何问题。相反，它确保了政府有足够的时间来做美国纳税人应得的尽职调查。“这正是<strong style="margin: 0px;padding: 0px;">四个提案</strong>所需的评估工作量，……我们只是一开始低估了所需花费的时间。”  </section><section style="margin: 8px 0px 0px;padding: 0px;">在宣布将合同授予从4月推迟到12月时，国防部官员对战略和方法充满信心，并且12月的时间表不会再次推迟。</section><section style="margin: 8px 0px 0px;padding: 0px;">该项目计划是1个为期3年的基础合同，外加2个1年的选择期。<strong>五年合同上限为</strong><span style="color: rgb(172, 57, 255);"><strong>90亿美元</strong></span>。在这个可能的五年采购结束时，国防部将发起“一场全面而公开的未来多云采购竞赛”。<span style="color: rgb(0, 0, 0);">华盛顿总部服务处</span>（Washington Headquarters Services）在DISA（国防信息系统局）的协助下领导采购工作。 </section><section style="margin-top: 8px;">JWCC可能与<strong>四家供应商</strong>签订<strong>四份</strong>单独的合同，并且根据任务所有者的要求，它们之间将在<strong>任务订单级别</strong>进行竞争。</section><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">JWCC被设想为</span><span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">作战司令部</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">和</span><span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">第四产业</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">机构的企业级能力。</span>虽然国防部并没有强制要求每个人都迁移到JWCC——尤其是<strong>军种</strong>（所有军种都在同时开展云计算工作<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">）</span>——但希望随着JWCC得到证实，更多的军种将过渡到它。<br/></section><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">JWCC</span>一旦授予后，官员们相信将获得<span style="color: rgb(172, 57, 255);"><strong>非密</strong></span>能力。授予后大约60天，将可以使用<span style="color: rgb(172, 57, 255);"><strong>涉密</strong></span>服务。不迟于授予后180天，将可以使用<span style="color: rgb(172, 57, 255);"><strong>绝密</strong></span>和<span style="color: rgb(172, 57, 255);"><strong>战术边缘</strong></span>服务。</section><p style="margin-top: 16px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;">美军的其它云项目 </strong><strong style="margin: 0px;padding: 0px;text-align: left;white-space: normal;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><section style="margin: 8px 0px 10px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: PingFangSC-light;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 2px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"/></section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;"><strong>1）空军Cloud One项目<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></strong></section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;">Cloud One是空军内部基于云的“通用开发、测试、生产计算环境”计划，允许团队和其他分支机构快速获取<strong>Microsoft Azure</strong>和 <strong>AWS</strong>云服务。<br/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">自2016年以来，<strong style="margin: 0px;padding: 0px;">Leidos</strong>（正是上面中标DES合同的那家公司）<strong style="margin: 0px;padding: 0px;">一直持有Cloud One合同</strong>，前身为<strong style="margin: 0px;padding: 0px;">空军云计算环境</strong>（Air Force Cloud Computing Environment），并由相关分包商提供支持。在此期间，空军将<strong style="margin: 0px;padding: 0px;">30多个应用程序</strong>迁移到商业云环境中。</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">但是，2020年1月，空军决定<span style="color: rgb(172, 57, 255);"><strong>解雇</strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Leidos</strong></span>，因为其提议的分包商之一存在组织利益冲突。这导致<strong style="margin: 0px;padding: 0px;">SAIC</strong>与空军签订为期五年、<strong style="margin: 0px;padding: 0px;">价值</strong><span style="color: rgb(172, 57, 255);"><strong style="margin: 0px;padding: 0px;">7.27亿</strong><strong style="margin: 0px;padding: 0px;">美元</strong></span>的Cloud One云计算合同。也就是说，<strong>SAIC将接手这项工作</strong>，继续为空军和其他军种整合向商业云的迁移。根据合同，将把大约<strong style="margin: 0px;padding: 0px;">800个空军和陆军应用程序迁移到云端</strong>。</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">在此期间，<strong>Leidos提出了抗议</strong>。而政府问责局（<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">GAO<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">）</span></span>最终驳回了该项抗议。</section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;">空军首席信息官<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">Lauren Knausenberger在接受采访时</span>：“<strong>我们不会等待JWCC</strong>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">”</span></section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;">虽然国防部希望在今年12月授予<strong>JWCC</strong>企业云合同，但空军仍计划继续构建其<strong>Cloud One</strong>平台作为其首选的云环境。</section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;">Knausenberger希望JWCC能够“很快”授予并取得成功，并表示它“至少可以为我们提供<strong>更好的计算定价</strong>”。“如果是这样，<strong>我们仍将使用Cloud One作为前门，我们将通过JWCC购买该计算</strong>。” </section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;">“如果它可以解<strong>决全球数据主权问</strong><strong>题</strong>，我可以利用世界上任何地方的任何数据中心，……你知道，数据在美国以外的地方会出现问题吗？” </section><p style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据在美国以外的地方会出现问题吗？Knausenberger非常期待，能够</span><span style="color: rgb(0, 0, 0);">通过<strong>JWCC</strong>解决<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">全球</strong></span><span style="color: rgb(172, 57, 255);"><strong>数据主权</strong></span><span style="color: rgb(0, 0, 0);"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">问</strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">题</strong></span>，解决<span style="color: rgb(172, 57, 255);"><strong>不同密级</strong></span><strong>之间传输数据</strong>的问题。因为现在的过程需要“<strong>许多、许多、许多、</strong><span style="color: rgb(172, 57, 255);"><strong>许多层次的批准</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">”。</span>这些都是希望JWCC能改变的事情。</p><p style="white-space: normal;margin-bottom: 0px;margin-top: 8px;"><br/></p><p style="white-space: normal;margin-bottom: 0px;margin-top: 8px;"><strong>2）应急部队的Dragon Cloud（龙云）项目</strong></p><section style="margin-top: 8px;">着眼于实现以数据为中心的战争，“美国的应急部队”正在云中运行不同于陆军以前运行过的任何工作负载。在过去几年中，<strong>第十八空降兵团</strong>（XVIII Airborne Corps）构建了Dragon Cloud。</section><p style="margin-top: 8px;">当自然灾害或人为危机发生，美国需要快速反应部队介入时，第十八空降兵团准备在世界任何地方部署。该部队由大约<strong>9.2万</strong>名士兵组成。</p><p style="margin-top: 8px;"><strong>龙云是</strong><span style="color: rgb(172, 57, 255);"><strong>战术云</strong></span>。该军团与AWS公司合作，推出了他们认为是常规陆军第一个持久的<strong>战术云</strong>——Dragon Cloud（龙云）。</p><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">非密云资源</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span>龙云首先开发了<strong>影响级别5</strong> (IL5) 的概念验证 (POC) 云环境，可托管符合政府法规的<span style="color: rgb(172, 57, 255);"><strong>非密</strong></span>数据和工作负载。</section><p style="margin-top: 8px;"><strong>涉密云资源</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span>在该POC成功的基础上，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">龙云</span>随后继续开发和改进一个可操作的云环境，可以处理<span style="color: rgb(172, 57, 255);"><strong>影响级别6</strong></span> (IL6) 的<span style="color: rgb(172, 57, 255);"><strong>涉密</strong></span>数据和工作负载。</p><section style="margin-top: 8px;"><strong>企业云vs.战术云</strong>。随着国防部准备授予<strong>JWCC</strong>合同并最终为<strong>企业云服务</strong>铺平道路，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">龙云</span>将标志为军方内部多个<strong>孤立</strong>的云驱动项目之一。</section><section style="white-space: normal;margin-bottom: 0px;margin-top: 8px;"><br/></section><p style="white-space: normal;margin-bottom: 0px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></p>



<p><a href="2247494806">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3e487411&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494806%26idx%3D1%26sn%3D7bd42a96f6448127b2adcdb00cb1afba%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 07 Aug 2022 06:53:00 +0800</pubDate>
    </item>
    <item>
      <title>致美国总统的零信任报告</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494739&amp;idx=1&amp;sn=75d45eb6ab1965ad361405b611fbaa27</link>
      <description>焦虑使人进步</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯学 &amp;amp; 启承</span> <span>2022-07-23 14:03</span> <span style="display: inline-block;">北京</span>
</p>

<p>焦虑使人进步</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2488b093&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNiaH3ZJCM9UFEr8qhXtM9BjAvMxg2SliblFdicFkGgZkSicSXrUmcOT1aR5vuYg8qYD6m5dOZKxhqbUg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文字不多  阅读<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;"><span style="text-align: left;">2022年</span>2月23日，<strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">总统国家安全电信咨询委员会</span></strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">（</span></span><span style="color: rgb(61, 167, 66);"><strong>NSTAC</strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">）</span>投票通过了一份<span style="color: rgb(172, 57, 255);"><strong><span style="text-align: left;">致拜登总统</span>的零信任报告</strong>《<strong>零信任和可信身份管理</strong>》</span>。<span style="color: rgb(61, 167, 66);"><strong>CISA</strong></span>（网络安全和基础设施安全局）在其官网上发布了该报告。</p><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;">在此前1个月（2022年1月26日<span style="text-align: left;">）</span>，</span><span style="letter-spacing: 0.544px;"><span style="text-align: left;">拜登</span>政府</span><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布了《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494558&amp;idx=1&amp;sn=24dbd295328876902a064e57eda63b7c&amp;chksm=97fa36f8a08dbfee8844aa785b4b15025e966101074a79de464767c050c9f18f96b98c5f2a92&amp;scene=21#wechat_redirect" textvalue="联邦政府零信任战略" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="text-decoration: underline;color: rgb(0, 82, 255);">联邦政府零信任战略</span></a><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">》</strong>，<span style="text-align: left;">对政府机构在<strong>两年半</strong>内实施零信任做出</span>计划要求<span style="text-align: left;">。</span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;">NSTAC</span>报告总体上做了<strong>两方面工作</strong>：</p><p style="text-align: left;margin-top: 10px;"><strong>一是给出了</strong><span style="color: rgb(172, 57, 255);"><strong>零信任实施模</strong><strong>型</strong></span>。即先通过<span style="color: rgb(61, 167, 66);"><strong>DAAS</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">（数据、应用程序、资产、服务）</span>来定义<strong>保护</strong><strong>面</strong></span>，然后采用<strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">五步流程法</span></strong><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">实施零信任。其中，使用<strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">Kipling方法</strong></span></strong><span style="outline: 0px;max-width: 100%;text-align: center;">编写</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">零信任策略</span></strong></span><span style="text-align: left;">，使用<strong>成熟度模型</strong>来度量<strong>零信任进展</strong>。</span></p><p style="text-align: left;margin-top: 10px;"><strong>二是提出了零信任实施的</strong><span style="color: rgb(172, 57, 255);"><strong>长期建议</strong></span>。为什么是“<strong>长期</strong>”？因为NSTAC认为：联邦政府零信任战略虽然名为“战略”，但只是关注了<strong>两年半的短期行为</strong>。而对于<strong>未来</strong><span style="color: rgb(0, 0, 0);"><strong>十年</strong></span>的考量，却存在疏忽。而NSTAC报告正是为了填补这一长远考量的空白。</p><p style="text-align: left;margin-top: 10px;"><strong><span style="text-align: left;">人有近忧又有远虑</span></strong><span style="text-align: left;">。笔者从<span style="text-align: left;">联邦政府零信任战略</span>和这份<span style="text-align: left;">NSTAC报告</span>中，看到了<strong>深深的焦虑</strong>：</span>如果说，<span style="color: rgb(61, 167, 66);"><strong><span style="text-align: left;">联邦政府零信任战略</span></strong>解决了<strong>两年半内的短期焦虑</strong></span><span style="color: rgb(0, 0, 0);">——给出了<strong>任务矩阵</strong></span>；那么，<span style="color: rgb(61, 167, 66);"><strong><span style="text-align: left;">NSTAC报告</span></strong>旨在解决<strong><span style="text-align: left;">两三年后的长期焦虑</span></strong></span><span style="text-align: left;">——</span><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">提出了</span><strong style="text-align: left;white-space: normal;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">24条建议</strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">和</span><strong style="text-align: left;white-space: normal;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">9条关键建议</strong><span style="text-align: left;">。</span></p><p style="text-align: left;margin-top: 10px;">注：NSTAC报告的PDF文档有<strong>56页</strong>，译文大概<strong>3.5万字</strong>。报告原文下载地址，参见本文<strong>图1</strong>下方。<br/></p></section></section></section></section></section><section style="margin-top: 15px;"><strong><span style="text-align: left;">关键词</span></strong><span style="text-align: left;">：<strong><span style="text-align: left;">NSTAC</span></strong>（总统国家安全电信咨询委员会）；<span style="text-align: left;"><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">DAAS</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（数据、应用程序、资产、服务）</span>；<strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">Kipling</span></strong><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">方法</span>；</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;color: rgb(0, 0, 0);"></span><strong><span style="text-align: left;">OMB</span></strong>（<span style="text-align: left;">管理和预算办公室</span>）；<strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">CISA</span></strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（网络安全和基础设施安全局）</span><span style="text-align: left;">；</span></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;color: rgb(0, 0, 0);">FISMA</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: left;color: rgb(0, 0, 0);">（<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">联邦信息安全管理法案</span>）；NIST<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（国家标准与技术研究所）</span></span></section><section style="text-align: center;margin-top: 15px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><section style="margin-top: 15px;">1.报告背景<br/></section><p>2.<span style="color: rgb(61, 167, 66);"><strong>零信任实施模型</strong></span><strong>（方法论）</strong><br/></p><p>3.报告建议条目</p><p>4.<span style="color: rgb(61, 167, 66);"><strong>九项关键建议</strong></span></p><p style="white-space: normal;">5.报告详细目录</p><p><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3062146892655366" data-s="300,640" data-w="885" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9e5b22db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOLF1n5DtTjSU6o4ZibftsEl714lRIfWXic9bdHXVgTCRvEhaJ4g28Hcv8CVoa0OGOl74dyLrVbNiaaA%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;">图1-报告首页</p><p style="margin-top: 10px;white-space: normal;text-align: left;"><strong>报告原文地址</strong>：</p><p style="margin-top: 10px;white-space: normal;text-align: left;"><a href="https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf" target="_blank">https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf</a><br/></p><p style="text-align: left;margin-top: 20px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">报告背景</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><p style="white-space: normal;margin-top: 10px;"><strong>总统国家安全电信咨询委员会（NSTAC）</strong>的职责是向总统办公厅（EOP）提供基于业界的分析和建议，说明政府如何制定政策或采取行动，以加强国家安全和应急准备（NS/EP）<strong>通信</strong>。<br/></p><section style="white-space: normal;margin-top: 20px;"><strong>1）三箭连发</strong></section><section style="margin-top: 10px;">2021年5月，<strong>白宫</strong>责成NSTAC开展一项<strong>多阶段</strong>研究任务<strong>“增强2021年之后的</strong><span style="color: rgb(172, 57, 255);"><strong>互联网弹性</strong></span><strong>”</strong>。该任务要求NSTAC研究对美国国家安全和应急准备至关重要的<strong>三个关键网络安全问题</strong>：<br/></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>商业信息和通信技术<strong>供应链</strong>中的<strong>软件保障</strong>。</p></li><li><p><strong>零信任和可信身份管理</strong>。</p></li><li><p>信息技术（IT）和运营技术（OT）的融合。</p></li></ol><section style="margin-top: 10px;">NSTAC已经在2021年11月提交了<strong>第1阶段</strong>的<strong>供应链</strong><strong>软件保障</strong>报告。这次提交的是<strong>第2阶段</strong>的《<strong style="white-space: normal;">零信任和可信身份管理</strong>》报告。而<strong>第3阶</strong>段的<strong>工业物联网安全</strong>还处于研究过程中。<br/></section><p style="margin-top: 20px;"><strong>2）战略延续</strong></p><section style="margin-top: 10px;"><span style="text-align: left;">2022年1月26日，</span><span style="text-align: left;letter-spacing: 0.544px;">拜登政府</span><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布了<span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494558&amp;idx=1&amp;sn=24dbd295328876902a064e57eda63b7c&amp;chksm=97fa36f8a08dbfee8844aa785b4b15025e966101074a79de464767c050c9f18f96b98c5f2a92&amp;scene=21#wechat_redirect" textvalue="联邦政府零信任战略" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="text-align: left;white-space: normal;" data-linktype="2"><span style="text-decoration: underline;color: rgb(0, 82, 255);">联邦政府零信任战略</span></a><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">》</strong></span>，要求各机构在<strong>2024财年结束</strong>之前（即<strong>2024年9月底</strong>之前，即<span style="color: rgb(0, 0, 0);"><strong>两年半</strong></span><strong>时间</strong>内），实现具体的零信任安全目标。这些目标按照零信任的<strong>五大支柱</strong>分别设置。</section><section style="margin-top: 10px;"><strong>NSTAC报告认为</strong>：当前和未来的政府必须将联邦零信任过渡视为国家的当务之急，并因此建立必要的领导优先顺序、资金和问责机制，以在<strong>未来十年</strong>维持政府对零信任的整体承诺。为了实现这一目标，NSTAC提出了<strong>24条建议</strong>和<strong>9条关键建议</strong>（参见本文的后文）。</section><p style="white-space: normal;margin-top: 20px;"><strong>3）主要内容</strong></p><section style="margin-top: 10px;">报告的主要内容是：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">第0章：概述报告<strong>摘要</strong>；</p></li><li><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">第1章：回顾<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">美国<strong>联邦政府零信任战</strong><strong>略</strong></span>；</p></li><li><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">第2章：介绍<strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">零信任实施模型</span></strong>，主要包括<strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">五步流程</span></strong>和<strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">成熟度模型</span></strong>；</p></li><li><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">第3章：<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">提出建议，解决<strong>联邦政府</strong>零信任战略实施的障碍；</span></p></li><li><p style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;">第4章：提出建议，</span><span style="letter-spacing: 0.544px;">解决<strong>非联邦实体</strong>零信任战略实施的障碍；</span></p></li></ul><section style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 10px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;">注：报告详细目录，放在了本文末尾。</span><span style="letter-spacing: 0.544px;"></span></section><p style="white-space: normal;margin-top: 20px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">零信任实施模型（方法论）</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><p style="margin-top: 15px;white-space: normal;"><span style="text-align: left;color: rgb(0, 0, 0);"><strong><strong style="white-space: normal;">NSTAC</strong></strong>总结了一套<strong>零信任实施模</strong><strong>型</strong>，本质是<strong>零信任实施</strong></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>方法论</strong></span><span style="text-align: left;">。它基于</span><strong style="text-align: left;white-space: normal;">保护</strong><strong style="text-align: left;white-space: normal;">面</strong>的概念<span style="text-align: left;">，采用</span><strong style="text-align: left;white-space: normal;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">五步流程法</span></strong><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">来</span><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">实施零信任，并</span><span style="text-align: left;">使用<strong>成熟度模型</strong>来度量<strong>零信任进展</strong>。</span></p><section style="margin-top: 15px;margin-bottom: 15px;white-space: normal;"><strong>1）定义保护面和DAAS<br/></strong></section><p style="white-space: normal;"><span style="color: rgb(172, 57, 255);"><strong>保护面</strong></span>：是零信任策略保护的区域。<br/></p><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><p>每个保护面都包含<strong>单个</strong><strong>DAAS</strong>（数据、应用程序、资产、服务）元素。</p></li><li><p>每个<strong>零信任环境</strong>可以包含<strong>多个</strong>保护面。</p></li><li><p><strong>零信任架构</strong>则以“<strong>每个保护面</strong>”为基础进行构思，由内而外设计，从保护面开始向外移动。<br/></p></li></ul><section style="white-space: normal;margin-top: 10px;"><span style="color: rgb(172, 57, 255);"><strong>DAAS</strong></span>（数据、应用程序、资产、服务）：进入单个保护面的敏感资源。</section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><p><strong>数据</strong>：如果泄露或误用，会造成最大风险的敏感数据。<span style="text-indent: 0em;">示例包括支付卡信息、受保护的健康信息、</span><span style="text-indent: 0em;">个人身份信息</span><span style="text-indent: 0em;">、</span><span style="text-indent: 0em;">知识产权。</span><span style="text-indent: 0em;">在政府背景下，</span><span style="text-indent: 0em;">还包括机密信息、国家安全信息</span><span style="text-indent: 0em;">、</span><span style="text-indent: 0em;">受控非</span><span style="text-indent: 0em;">密信息。</span></p></li><li><p><strong>应用程序</strong>：使用敏感数据或控制关键资产的应用程序。</p></li><li><p><strong>资产</strong>：包括组织的信息技术（IT）、运营技术（OT）、物联网设备。</p></li><li><p><strong>服务</strong>：组织最依赖的服务。示例包括域名系统（DNS）、动态主机配置协议（DHCP）、目录服务、网络时间协议（NTP）、定制的应用程序编程接口（API）。</p></li></ul><p style="margin-bottom: 15px;white-space: normal;margin-top: 20px;"><strong>2）梳理<span style="text-align: center;">零信任实施五步流程</span></strong><br/></p><p style="white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.2675" data-w="2000" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9b97b515&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPJuIxAibg5HnzczLYzf6lmEeGaSA0j4nrG5bJpsgxUvu0N45oHc6ovPwicobm1GHLoBGAueDaD7sNw%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;text-align: center;">图2-零信任实施五步流程（极简版）</p><section style="margin-top: 15px;margin-bottom: 15px;white-space: normal;"><span style="text-align: center;"></span>对上面这五步流程的具体描述，如下表所示：<br/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.8179530201342282" data-w="1192" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d1be1090&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNqtmM35Xyw1usUa3I2JOhalfwF2e8TH1R2OmZ3iaCRU2s8k1I8NPLiaZdicJQhqDq6ZkUw7skDgsKHw%2F640%3Fwx_fmt%3Dpng"/></section><p style="white-space: normal;text-align: center;">表3-零信任实施五步流程（含可量化进度指标）</p><p style="margin-bottom: 15px;white-space: normal;margin-top: 20px;"><strong>3）给出零信任成熟度模型</strong></p><section style="margin-top: 15px;margin-bottom: 15px;white-space: normal;">报告在附录A中给出了<strong>零信任成熟度模型</strong>。<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">该模型将</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">零信任成熟度</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（横向维度）与</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">零信任实施五步流程</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（纵向维度）相结合。</span>如下所示：</section><section style="margin-top: 15px;margin-bottom: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="1.2640449438202248" data-w="890" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=61f5d98e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNiaH3ZJCM9UFEr8qhXtM9Bj6LE1LtA3npkdr2C4FwxZpHskCeNiaIAfFgPJiad7JbmvCC7l30CFZvqg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 15px;white-space: normal;text-align: center;">表4-<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">NSTAC</span>零信任成熟度模型<br/></section><p style="margin-bottom: 15px;white-space: normal;margin-top: 10px;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="white-space: normal;">联邦零信任战略</strong>中引用了<strong style="white-space: normal;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;">CISA零信任成熟度模型</strong>。笔者对比了</span><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">NSTAC</span><span style="text-align: center;">零信任成熟度模型</span></strong>与<strong style="white-space: normal;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;">CISA零信任成熟度模型</strong>，发现主要区别是：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-bottom: 15px;white-space: normal;margin-top: 10px;"><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="text-align: center;">成熟度</strong>维度不同</span></strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">：</span><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="letter-spacing: 0.544px;">CISA模型</strong></span></strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">的</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><span style="text-align: center;">成熟度</span></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">划分为</span><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong>3个阶段</strong></span></strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">，即传统、高级、最优</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">；而</span><strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">NSTAC</span><span style="text-align: center;">模型</span></strong><span style="text-align: center;">的</span><span style="text-align: center;">成熟度划分为<strong>5个阶段</strong>，即初始、可重复、定义、管理、优化。</span></p></li><li><p style="margin-top: 0px;"><strong><span style="text-align: center;">另一个维度不同</span></strong><span style="text-align: center;">：<strong style="white-space: normal;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="letter-spacing: 0.544px;">CISA模型</strong></span></strong>的<span style="text-align: center;">另一个维度是<strong>五大支柱</strong>，即身份、设备、网络、应用程序工作负载、数据；而<strong style="white-space: normal;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">NSTAC</span><span style="text-align: center;">模型<span style="text-align: center;"></span></span></strong><span style="text-align: center;"><span style="text-align: center;">的</span><span style="text-align: center;">另一个维度是<strong>五步流程</strong>，如图2和图3所示。</span></span></span></span></p></li></ul><p style="margin-top: 20px;"><strong><span style="text-align: center;">4）使用<strong>Kipling方法</strong>编写零信任策略</span></strong></p><section style="white-space: normal;margin-top: 10px;"><strong>Kipling方法</strong>：是一种创建<strong>零信任策略</strong>的方法，描述了资源访问的人员、内容、时间、地点、原因、方式（Who, What, When, Where, Why, How）：</section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><p>Who：应该允许谁访问资源？</p></li><li><p>What：允许断言的身份用于访问资源的应用程序是什么？</p></li><li><p>When：何时允许断言的身份访问资源？</p></li><li><p>Where：资源位于哪里？</p></li><li><p>Why：为什么允许用户（Who）访问资源？</p></li><li><p>How：流量访问资源时应如何处理？</p></li></ul><section style="margin-top: 10px;white-space: normal;">作为示例，报告在附录B中，采用Kipling方法，给出了目录服务管理员的<strong>零信任策略</strong>示例：</section><section style="margin-top: 10px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.25944333996023855" data-w="1006" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a6ce5fb1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNqtmM35Xyw1usUa3I2JOhaQHssmKnRLMZCibe7IZxVTibK8ukgGFE5iahxxYxlo6gficTGb7yRPwmjOA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 10px;white-space: normal;text-align: center;">表5-目录服务管理员的零信任策略示例<br/></section><section style="margin-top: 10px;white-space: normal;"><strong>表中这条零信任策略的具体含义是</strong>：成功完成MFA<span style="text-align: left;">（</span><span style="text-align: left;">多因素认证）</span>的管理员用户（由组成员身份而非源IP地址定义），可以在通过IDS（入侵检测系统）和DPI（深度数据包检查）检查后的任何时间（24/7），使用“目录管理工具应用”（Directory Admin Tool App）（由web/client-server/SSH而不是端口和协议定义），访问“Dir_Server_Loc（目录服务器位置）” （由工作负载上的标签而非目标IP地址定义）的服务器，因为他需要管理目录服务的“元数据”。</section><section style="margin-top: 10px;white-space: normal;">笔者对<strong>Kipling方法</strong>实在是太喜欢，于是就尝试寻找它的来源。结果发现它真地就是经典的&#34;<span style="color: rgb(172, 57, 255);"><strong>5W1H</strong></span>&#34;<strong>方法论</strong>。</section><section style="margin-top: 10px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7037896365042536" data-s="300,640" data-w="1293" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9ed04b59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNqtmM35Xyw1usUa3I2JOhajibLbDGanGibaTypwA4Z8sYDeQicxpZiahQooNUplSf3REXeh4dTiaWN35w%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 10px;white-space: normal;text-align: center;">图6-Kipling<strong style="white-space: normal;"></strong></section><section style="margin-top: 10px;white-space: normal;">诺贝尔文学奖得主、英国作家<strong>Kipling</strong>在1902年出版的《原来如此故事集》中写道：</section><section style="white-space: normal;text-indent: 2em;">我有六个诚实的仆人，</section><section style="white-space: normal;text-indent: 2em;">他们教会了我所知道的一切。</section><section style="white-space: normal;text-indent: 2em;">他们的名字是What和Why和When</section><section style="white-space: normal;text-indent: 2em;"><span style="font-family: &#34;Microsoft Yahei&#34;, 微软雅黑, arial, 宋体, sans-serif;font-size: 16px;background-color: rgb(255, 255, 255);">和How和Where和Who。</span></section><p style="margin-bottom: 15px;white-space: normal;margin-top: 20px;"><strong>5）给出了零信任成熟度模型的示例</strong><br/></p><section style="margin-top: 10px;white-space: normal;"><span style="text-align: center;">由于<strong>目录服务</strong>是控制访问权限的核心，因此它是攻击者的主要目标。</span><span style="text-align: center;">在零信任上下文中，目录服务是支持身份认证和授权的底层基础设施。</span><span style="text-align: center;">它的失陷会使任何零信任的实施变得无效。</span><span style="text-align: center;">所以，报告专门在附录B中给出了目录服务的</span>零信任成熟度模型示例。</section><section style="margin-top: 10px;white-space: normal;">对于其它类型的关键性服务，可以参考这个示例，制定零信任实施成熟度模型。</section><p style="margin-top: 20px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">报告建议条目</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="white-space: normal;margin-top: 15px;"><br/></section><section style="white-space: normal;margin-top: 15px;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">NSTAC</span>报告中所有建议的条目如下：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><strong>24条建议</strong>：除了<strong>粗体</strong>标记的条目（即5个标题），其它所有条目正好构成24条建议。</p></li><li><p><strong>9条关键建议</strong>：以<strong><span style="color: rgb(61, 167, 66);">绿色</span></strong>标记的条目，是报告声称的最关键的9条建议。</p></li></ul><section style="white-space: normal;margin-top: 15px;"><strong>3. 解决联邦政府零信任战略实施的障碍和促进因素</strong></section><p style="white-space: normal;"><strong>3.1. 解决监督问题并建立成熟度指标</strong></p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">3.1.1. 通过零信任战略实施的进度指标，加强问责制</span></p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">3.1.2. 通过进度指标，提高透明度并支持持续改进</span></p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">3.1.3. 成立工作组，为关键联邦企业基础设施服务开发零信任成熟度模型</span></p><p style="white-space: normal;"><strong>3.2. 解决治理障碍和促进因素，以实现联邦对零信任的持续承诺</strong></p><p style="white-space: normal;">3.2.1. 将零信任原则纳入联邦网络安全政策</p><p><span style="color: rgb(61, 167, 66);">3.2.1.1 阐明零信任战略与FISMA要求之间的一致性</span></p><p>3.2.1.2 自动化FISMA合规任务</p><p style="white-space: normal;">3.2.2. 将零信任实践纳入联邦网络安全技术计划</p><p>3.2.2.1 利用CISA网络安全部门的计划和服务</p><p>3.2.2.2 明确将CISA的CDM(持续诊断和缓解)计划与零信任对齐</p><p><span style="color: rgb(61, 167, 66);">3.2.2.3 建立一个民间零信任项目办公室</span></p><p><span style="color: rgb(61, 167, 66);">3.2.2.4 优先创建CISA共享安全服务，以<span style="color: rgb(61, 167, 66);">发现</span>互联网可访问资产</span></p><p>3.2.2.5 在拟定的民用和国防零信任计划办公室之间建立协同关系</p><p style="white-space: normal;">3.2.3. 将零信任实践纳入联邦网络安全预算和采购流程</p><p>3.2.3.1 扩大采购工具的范围</p><p>3.2.3.2 鼓励各部门和机构为零信任确定额外资金</p><p>3.2.3.3 在联邦技术采购中传达对零信任的支持</p><p style="white-space: normal;"><strong>3.3. 解决技术障碍和促进因素，以实现联邦对零信任的持续承诺</strong></p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">3.3.1. 在特别出版物中评估零信任生态系统技术互操作性</span></p><p style="white-space: normal;">3.3.2. 鼓励采用云计算</p><p style="white-space: normal;">3.3.3. 探索新的可信身份管理方法</p><p style="white-space: normal;"><strong>4. 发挥联邦政府在激励非联邦零信任采纳方面的作用</strong></p><p style="white-space: normal;">4.1. 提高和维系公众意识</p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">4.2. 制定和完善标准和指南，包括国际标准和指南</span></p><p style="white-space: normal;"><span style="color: rgb(61, 167, 66);">4.3. 在为IT安全现代化提供的联邦拨款中激励零信任</span></p><p style="white-space: normal;">4.4. 在联邦采购中考虑对零信任的偏好</p><p style="white-space: normal;">4.5. 考虑监管<span style="color: rgb(0, 0, 0);">救助行动</span></p><section style="white-space: normal;margin-top: 20px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">九项关键建议</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;"><br/></section><section style="margin-top: 15px;">下面对报告中最关键的九项建议，展开其内容。笔者也分别做了“<strong style="white-space: normal;">评论</strong>”。而更多的详情，可以参见报告原文中的对应章节。</section><section style="margin-top: 15px;"><strong>1）加强<strong style="color: rgb(172, 57, 255);white-space: normal;">问责制</strong>，以度量联邦零信任</strong><span style="color: rgb(172, 57, 255);"><strong>进展</strong></span><strong>（对应于3.1.1节）</strong></section><section style="margin-top: 15px;">联邦首席信息安全官（<strong>CISO</strong>）应该与<strong>国家网络总监</strong>（National Cyber Director）密切合作，针对零信任最佳实践，制定基于<span style="color: rgb(172, 57, 255);"><strong>进度指标</strong></span>的报告要求，如表3中的第3列所示。<strong>报告责任</strong>需在<strong>机构CISO或以上级别</strong>。</section><section style="margin-top: 15px;"><em><strong>评论</strong>：美国政府实在是太擅长搞<strong>量化指标</strong>了！用量化指标来评估效果，才能有效问责。</em></section><section style="margin-top: 15px;"><strong>2）提高联邦零信任进程的</strong><span style="color: rgb(172, 57, 255);"><strong>透明度</strong></span><strong>（对应于3.1.2节）</strong></section><section style="margin-top: 15px;">联邦政府必须致力于在记录零信任进程中的<span style="color: rgb(172, 57, 255);"><strong>经验教训</strong></span>方面保持透明度，在政府内部培养<strong>持续改进的文化</strong>，并教育更加广泛的国家生态系统。管理和预算办公室（OMB）应要求<strong>各机构</strong><span style="color: rgb(172, 57, 255);"><strong>每年至少发布一个零信任用例</strong></span><strong>，记录实施经验教训</strong>。OMB应与美国NIST（国家标准与技术研究所）共同召开年度工作组会议，审查用例，并在适当情况下更新现有的联邦零信任指南和标准。</section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：既然大家都知道零信任不那么容易落地，就请把各家踩过的坑、绕过的弯都如实共享出来，照亮后人的前行之路吧。</em></section><section style="margin-top: 15px;"><strong>3）为关键的</strong><span style="color: rgb(172, 57, 255);"><strong>联邦企业基础设施服务</strong></span><strong>开发零信任成熟度模型（对应于3.1.3节）</strong><br/></section><section style="margin-top: 15px;">OMB应通过联邦CISO委员会开展全面的流程，以识别目前在联邦机构中普遍存在并可能至少在未来5年内继续存在的<strong>企业基础设施服务</strong>。一旦确定这些服务后，联邦CISO委员会应成立一个<strong>跨机构工作组</strong>，为<strong>保护每项服务</strong>创建相应的零信任成熟度模型，可以参考附录B中NSTAC为<strong>目录服务</strong>（如Active Directory）创建的零信任成熟度模型示例。</section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：一定要对“联邦<strong>企业</strong>基础设施服务”有正确的理解！“<strong>企业</strong>”一词是企业级/全局性/整体性之意，而非一家具体的企业。</em></section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：<strong>企业基础设施服务</strong>有哪些呢？示例包括目录服务、域名系统（DNS）、动态主机配置协议（DHCP）、网络时间协议（NTP）等。NSTAC希望为所有关键企业基础设施服务，创建相应的零信任成熟度模型。</em></section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：为什么要选择<strong>目录服务</strong>作为示例？因为它是核心企业服务，几乎所有联邦机构都要用到它，而且这种情况可能还会持续至少十年。</em></section><section style="margin-top: 15px;"><strong>4）将零信任原则与关键治理和合规框架相一致（对应于3.2.1.1<strong style="white-space: normal;">节</strong>）</strong><br/></section><section style="margin-top: 15px;">OMB应发布一份备忘录，澄清零信任战略原则与<strong>FISMA</strong>（联邦信息安全管理法案）及其相关标准<strong>NIST800-53</strong>（信息系统和组织的安全控制）的机构合规要求之间的战略一致性。此外，<strong>OMB应责成NIST编制一份特别出版物（SP），</strong><span style="color: rgb(172, 57, 255);"><strong>将零信任映射到NIST SP-800-53的安全控制</strong></span>，以避免机构遇到其<strong>常规的合规义务</strong>与<strong>长期的零信任转型</strong>之间的<strong>冲突</strong>。</section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：这一招比较狠！直接给NIST派了工单：将零信任能力映射到NIST SP-800-53的安全控制项。如果真地能做出这个映射，零信任的落地难题就更容易解决了，对零信任的符合性验证也更简单了。笔者非常期待！</em></section><section style="margin-top: 15px;"><strong>5）建立一个</strong><span style="color: rgb(172, 57, 255);"><strong>民用</strong></span><strong>零信任项目办公室（对应于3.2.2.3节）</strong><br/></section><section style="margin-top: 15px;">网络安全和基础设施安全局（CISA）应为<strong>联邦民用机构</strong>建立一个专用的零信任项目办公室，以托管实施指南、参考架构、能力目录、培训模块，并通常作为一个零信任的民间政府知识管理中心。在可行的范围内，民用零信任项目办公室应与最近成立的<span style="color: rgb(172, 57, 255);"><strong>国防部</strong></span><strong>零信任项目办公室</strong>协作并分享最佳实践。</section><section style="margin-top: 15px;white-space: normal;"><em><strong>评论</strong>：有军用，就该有民用。军民融合，不难理解。</em></section><section style="margin-top: 15px;"><strong>6）创建CISA零信任</strong><span style="color: rgb(172, 57, 255);"><strong>共享安全服务</strong></span><strong>以发现为互联网可访问资产（<strong style="white-space: normal;">对应于3.2.2.4<strong style="white-space: normal;">节</strong></strong>）</strong><br/></section><section style="margin-top: 15px;">CISA应阐明其现有共享服务技术产品如何帮助机构实现零信任。此外，CISA应建立一项新的共享服务，以帮助机构“<strong>全面了解其</strong><span style="color: rgb(172, 57, 255);"><strong>互联网可访问资产</strong></span>”，这是任何开始实施零信任的机构所应具备的<strong>基础能力</strong>，正如《联邦零信任战略》中明确强调的那样。 </section><section style="margin-top: 15px;"><em><strong>评论</strong>：为什么<strong>各个机构的</strong><strong style="white-space: normal;">互联网暴露资产</strong>还需要<strong>政府的共享服务</strong>来发现呢？这只能说明：发现和跟踪<em style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">机构</em>的互联网暴露资产，对机构自身来说具有很大挑战性。这也正是Gartner所提的<strong>外部攻击面管理（EASM）</strong>能力。由于这种<strong>可见性</strong>非常重要，机构自己又搞不定，只好请出安全管家CISA，把它做成一项共享型安全服务，普惠所有政府机构，避免安全短板效应。</em></section><section style="margin-top: 15px;"><strong>7）评估零信任生态系统技术</strong><span style="color: rgb(172, 57, 255);"><strong>互操作性</strong></span><strong><strong style="white-space: normal;">（<strong>对应于3.3.1<strong style="white-space: normal;">节</strong></strong>）</strong></strong></section><section style="margin-top: 15px;">作为国家网络安全卓越中心（NCCoE）现有零信任工作的延伸，NIST应该评估商业、政府、开源零信任技术解决方案生态系统的技术互操作性。该NIST出版物应该输出未来的政策和投资建议，以提高零信任架构的采用效率。</section><section style="margin-top: 15px;"><em><strong>评论</strong>：关于零信任生态系统的技术互操作性，几乎是每篇零信任建议书的必谈内容。这里就不再赘述了。<br/></em></section><section style="margin-top: 15px;"><strong>8）推进在</strong><span style="color: rgb(172, 57, 255);"><strong>国际</strong></span><span style="color: rgb(172, 57, 255);"><strong>标准</strong></span><strong>机构中的零信任<strong style="white-space: normal;">（<strong>对应于4.2<strong style="white-space: normal;">节</strong></strong>）</strong></strong></section><section style="margin-top: 15px;">美国政府在NIST的领导下，与行业合作伙伴密切合作，<strong>应该启动一条</strong><span style="color: rgb(172, 57, 255);"><strong>多年</strong></span><strong>的路径，在国际标准机构内部推进零信任</strong>。当前零信任指南的持续成熟至关重要；当它们演变为基于共识、得到广泛认可的国际标准，就可以成为美国政府鼓励在全国范围内采用零信任的各种政策行动的基础，正像<strong>NIST网络安全框架</strong>所做的那样。</section><section style="margin-top: 15px;"><em><strong>评论</strong>：这个建议很有趣，但也很自然。由于美国的NIST网络安全框架（CSF）已经成为<strong>国际性</strong>的事实标准，它自然也就成为零信任的榜样。如果能将零信任从美国标准推广为国际性标准，当然就更好地保障了零信任的发展方向。</em></section><section style="margin-top: 15px;"><strong>9）优先考虑在联邦IT现代化拨款中采用零信任<strong style="white-space: normal;">（<strong>对应于4.3<strong style="white-space: normal;">节</strong></strong>）</strong></strong></section><section style="margin-top: 15px;">CISA应在其自由裁量权中优先考虑零信任项目，以便为各州和地方授予IT安全现代化拨款。在CISA对《州和地方网络安全促进法案》（属于《基础设施投资和就业法案》（IIJA）的一部分）的管理中，这一机会尤其明显。根据该法案，他们将在未来4年（至2026年）投入10亿美元。交通部长、商务部长、能源部长根据IIJA的规定，还拥有自由裁量权，要求资金接收者证明“良好的网络安全实践”，作为在其管辖范围内接收资金的条件。他们应该酌情行使这一权力，鼓励采纳零信任原则。</section><section style="margin-top: 15px;"><em><strong>评论</strong>：千言万语一句话，有钱才是好“爸爸”。只要资金预算和拨款都朝着零信任项目倾斜，还有什么搞不定的呢！</em></section><p style="margin-top: 20px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">报告详细目录</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><p style="margin-top: 15px;white-space: normal;"><strong>0. 执行摘要<br/></strong></p><section style="text-indent: 0em;">0.1 报告焦点和范围</section><p>0.2 关键结论的摘要</p><p>0.3 建议的摘要</p><p>0.4 九项关键建议的详细信息</p><p><strong>1. 介绍零信任和美国联邦政府的零信任战略</strong></p><p>1.1. 零信任的历史和基本原则</p><p>1.2. 零信任和联邦政府的网络安全战略</p><p><strong>2. 零信任实施的业界标准和最佳实践</strong></p><p>2.1. 零信任实施的业界模型</p><p>2.1.1. 零信任实施的五步流程</p><p>2.1.2. 零信任成熟度模型</p><p>2.2. 促进零信任的业界技术能力</p><p><strong>3. 解决联邦政府零信任战略实施的障碍和促进因素</strong></p><p>3.1. 解决监督问题并建立成熟度指标</p><p>3.1.1. 通过零信任战略实施的进度指标，加强问责制</p><p>3.1.2. 通过进度指标，提高透明度并支持持续改进</p><p>3.1.3. 成立工作组，为关键的联邦企业基础设施服务开发零信任成熟度模型</p><p>3.2. 解决治理障碍和促进因素，以实现联邦对零信任的持续承诺</p><p>3.2.1. 将零信任原则纳入联邦网络安全政策</p><p>3.2.2. 将零信任实践纳入联邦网络安全技术计划</p><p>3.2.3. 将零信任实践纳入联邦网络安全预算和采购流程</p><p>3.3. 解决技术障碍和促进因素，以实现联邦对零信任的持续承诺</p><p>3.3.1. 在特别出版物中评估零信任生态系统技术互操作性</p><p>3.3.2. 鼓励采用云计算</p><p>3.3.3. 探索新的可信身份管理方法</p><p><strong>4. 发挥联邦政府在激励非联邦零信任采纳方面的作用</strong></p><p>4.1. 提高和维系公众意识</p><p>4.2. 制定和完善标准和指南，包括国际标准和指南</p><p>4.3. 在为IT安全现代化提供的联邦拨款中激励零信任</p><p>4.4. 在联邦采购中考虑对零信任的偏好</p><p>4.5. 考虑监管<span style="color: rgb(255, 0, 0);"><span style="color: rgb(0, 0, 0);">救助</span></span>行动</p><p><strong>5. 结论</strong></p><p><strong>附录A. 零信任成熟度模型</strong></p><p><strong>附录B. 零信任成熟度模型的示例：目录服务</strong></p><p>附录C. 成员和参与者</p><p>附录D. 缩略词</p><p>附录E. 定义</p><p>附录F. 参考文献</p><p><br/></p><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></section><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;"></span></section>



<p><a href="2247494739">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a906e764&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494739%26idx%3D1%26sn%3D75d45eb6ab1965ad361405b611fbaa27%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 23 Jul 2022 14:03:00 +0800</pubDate>
    </item>
    <item>
      <title>数据访问控制的未来</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494737&amp;idx=1&amp;sn=503149c7dfc7b91d6bd16c6de6b11721</link>
      <description>原生控制&gt;数据代理&gt;数据边车</description>
      <content:encoded><![CDATA[<p>
原创 <span>一帆 &amp;amp; 柯学</span> <span>2022-07-04 06:36</span> <span style="display: inline-block;">北京</span>
</p>

<p>原生控制>数据代理>数据边车</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2c657433&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPOFbu8GQunvVyiaZjsfUABx5bU50huYgibibvnwBRk3QDbcblSSOrmxSPHdFoX9WznVkCyicJ7KnicNWdg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;margin-bottom: 0px;">全文约<span style="color: rgb(0, 0, 0);"><strong>40</strong><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>8</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;margin-bottom: 0px;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">数据访问控制</strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">是<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;visibility: visible;">零信任</strong>的</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">最后环节</strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">和</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">终极目标</strong><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);visibility: visible;">。</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">基于零信任的数据访问控制</strong>，已经成为<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">数据安全保护和治理的新方法</strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。</span></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">但是，对于数据访问控制的</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(61, 167, 66);display: inline !important;"><strong>实施</strong></span><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><strong>问题</strong>，企业客户却不得不面对几种选择：</span></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">1）基于<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据存储原生控制</strong>的方法：是指<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">利用</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据存储的原生控制能力</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">，来</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">构建自己需要的数据访问控制。<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">企业客户可以自己动手构建<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">DIY(自己动手)</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">解决方案，也可以花钱购买<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据访问编排</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">解决</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">方案。但都无法摆脱<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据存储原生控制存在</span><span style="margin: 0px;padding: 0px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">可观察性不足</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">的问题。</span></span></span></span></span><br/></span></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="background-color: rgb(255, 255, 255);color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">2）基于<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据访问代理<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">的方法：<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">通过在<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据消费者</strong>(<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">用户/应用程序)和</span><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据存储</strong><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">之间</span></span></span></strong></span><strong style="background-color: rgb(255, 255, 255);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: 400;text-align: justify;letter-spacing: 0.544px;">建立独立的<strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据访问层</strong><span style="letter-spacing: 0.544px;">，</span>将访问控制与数据存储基础设施分离。<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;">这是<span style="margin: 0px;padding: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">目前主流的商用</span><span style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;color: rgb(61, 167, 66);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据访问平台</strong></span><span style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">采用的方式，也是当前最被看好的数据访问控制方法。<span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">但<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">传统的数据库代理技术</span>主要用于<strong style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">南北向</strong></span></span></span></strong></span></strong><strong style="background-color: rgb(255, 255, 255);"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-weight: 400;text-align: justify;letter-spacing: 0.544px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-indent: 0px;"><span style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">的流量控制，且难以适应于</span><strong style="margin: 0px;padding: 0px;color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">云原生微服务</strong><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">环境。</span></span></strong></span></strong></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(34, 34, 34);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">3）基于<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据层边车</strong>的方法：<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">将<strong>服务网格</strong>(Service Mesh)中的<strong>边车(Sidecar)</strong>技术理念，应用到<strong>数据网格</strong>(Data Mesh)，专门解决云原生微服务环境中的</span></span><span style="font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;color: rgb(61, 167, 66);display: inline !important;"><strong>东西向</strong></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">数据访问控制难题。数据层边车本质上充当<strong>应用程序和数据之间的</strong><strong>断路器</strong>。<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"></strong>尽管数据层边车还是发挥<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">代理</strong>的作用，但它是为<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">云原生架构</strong>和<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;">数据网格架构</strong>而设计的<strong>未来型代理</strong>。<strong style="margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"></strong></span></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">虽然新一代技术常常代表了未来的方向，但是企业客户还是应该结合自身的实际情况，选择最适合的<strong>数据访问控制实施方案</strong>。</span></section></section></section></section></section></section><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section style="white-space: normal;margin-bottom: 0px;"><strong>1.数据存储原生控制方法<br/></strong></section><section style="text-indent: 2em;">1）<strong>DIY(自己动手)</strong>解决方案</section><section style="text-indent: 2em;">2）<strong>数据访问编排</strong>解决方案</section><section style="text-indent: 2em;">3）数据存储库的<span style="color: rgb(61, 167, 66);"><strong>可观察性不足</strong></span></section><p><strong>2.数据访问代理方法<br/></strong></p><section style="text-indent: 2em;">1）代理和<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据库代</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">理</span></section><section style="text-indent: 2em;"><span style="text-indent: 2em;">2）SQL</span><strong>无感知</strong><span style="text-indent: 2em;">数据库代理</span><br/></section><section style="text-indent: 2em;">3）SQL<strong>感知</strong>数据库代理</section><p><strong>3.数据层边车方法</strong></p><section style="text-indent: 2em;">1）传统代理无法适应云原生环境</section><section style="text-indent: 2em;">2）<strong>云原生</strong>世界需要数据层边车</section><section style="text-indent: 2em;">3）<span style="color: rgb(61, 167, 66);"><strong>数据层边车 vs. 数据库代理</strong></span></section><p style="margin-bottom: 0px;"><br/></p><p style="margin-bottom: 0px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">数据存储原生控制方法</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></p><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据存储原生控制方法可以细分为两种方案：<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">DIY(自己动手)解决方案+数据访问编排方案。</span></p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>1）DIY（自己动手）解决方案</strong></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>方法说明</strong>。DIY（自己动手）解决方案是指客户利用<strong>数据存储原生能力</strong>，<span style="color: rgb(61, 167, 66);"><strong>自己动手</strong></span>构建客户需要的数据访问控制。<br/></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;">原生功能包括数据存储中可用的<strong style="margin: 0px;padding: 0px;">安全视图、函数、策略</strong>。<br style="margin: 0px;padding: 0px;"/></section></li><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;">如果客户的<strong>数据团队</strong>有能力利用数据存储中的原生功能，他们通常会这样做。</section></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>方法不足</strong>。使用原生能力构建DIY（自己动手）解决方案的<strong>问题</strong>在于：</section><ul class="list-paddingleft-1" style="margin: 0px;padding: 0px 0px 0px 1.2em;box-sizing: border-box;width: 577.417px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;list-style-type: disc;"><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong>它不是核心业务</strong>。在大多数情况下，利用原生功能构建DIY数据访问控制方案，并不是客户的高优先级事项。客户的工程资源最好用于支持和发展客户业务的核心活动，从而为企业创造更大的业务价值。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong>维护成本高</strong>。数据访问控制不是那种“<strong>设置好后就可以抛之脑后</strong>”的东西，它需要持续、悉心的照料，这会带来隐性成本和风险。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong>学习曲线陡峭</strong>。很多时候，如果您缺乏创建或管理数据访问解决方案的经验，此类项目可能会带来未知的工程挑战。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong>迁移数据平台的烦恼</strong>。如果客户想从一个数据平台迁移到另一个数据平台，可能需要<strong>重新编写</strong>DIY解决方案的大部分内容。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;">原生功能受限</strong>。DIY解决方案受限于可用的数据存储原生能力。参见下文。</p></li></ul><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br/></section><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;">2）数据访问编排解决方案</strong></p><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">方法说明</strong></strong>。数据访问编排解决方案是对<strong style="margin: 0px;padding: 0px;">原生数据存储能力</strong>进行<strong>编排</strong>的产品，只需要<span style="color: rgb(61, 167, 66);"><strong>付费购买</strong></span>即可，无需客户自己的数据团队亲自动手实现它们。</p><ul class="list-paddingleft-1" style="margin: 0px;padding: 0px 0px 0px 1.2em;box-sizing: border-box;width: 577.417px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;list-style-type: disc;"><li><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;">数据编排通常由软件平台支持，该平台连接各种<strong>存储系统</strong>，并在需要时启用与其他<strong>应用程序</strong>的连接。它将来自多个存储位置的数据进行整合，以便企业可以在其分析和管理平台中使用这些数据。</p></li><li><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;">在数据访问编排中，<strong>被编排的是对数据的访问，而非数据本身</strong>。不是在数据存储本身（例如数据库、数据仓库和数据湖）中手动配置数据访问，而是<span style="color: rgb(61, 167, 66);"><strong>使用单个工具定义访问策略</strong></span><strong>，然后在各种数据存储中执行安全策略</strong>。</p></li><li><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;">编排解决方案可能会节省客户利用原生能力构建方案的时间。<br/></p></li></ul><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">方法</strong>不足</strong>。与后文介绍的<strong>数据访问代理</strong>方案相比，编排解决方案在许多方面受到限制：</p><ul class="list-paddingleft-1" style="margin: 0px;padding: 0px 0px 0px 1.2em;box-sizing: border-box;width: 577.417px;list-style-type: disc;"><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;">缺乏数据感知能力</strong>。通常来说，编排解决方案依赖于定期批处理，来识别和标记敏感数据。而数据访问代理平台则能够在访问数据的同时对其进行分析，可以即时发现敏感信息并立即采取行动。</p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong>侵入性</strong>。编排解决方案经常会使用抽象数据访问所需的对象，<strong>污染数据基础设施</strong>。此外，在许多情况下，它们会迫使您<strong>更改现有逻辑</strong>（例如访问新的抽象对象而非现有对象）。而使用<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据访问代理</span>，则无需添加任何数据库对象，也无需改变查询中的任何内容。<br/></p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;">超级管理员凭据使用</strong>。编排解决方案需要使用<strong>高访问权限账户</strong>。这意味着您可能需要设置一个账户，能在SaaS或设备上执行很多操作（即创建对象和读取数据）。而使用<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据访问代理</span>，您无需添加任何额外的凭据，从而消除了意外更改的风险。</p></li><li style="margin: 0px;padding: 0px;clear: both;"><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;">原生功能受限</strong>。编排解决方案受限于可用的数据存储原生能力。参见下文。</p></li></ul><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><br/></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong>3）<strong>数据存储库的“</strong><span style="font-weight: 400;color: rgb(61, 167, 66);"><strong>可观察性不足</strong></span><strong>”</strong></strong></section><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据存储库存在“<span style="color: rgb(0, 0, 0);">可观察性不足</span>”的问题。</p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>3.1）数据存储库日志通常被禁用</strong></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;">在传统的本地数据库和DBaaS（数据库即服务）中，<strong>日志的唯一来源</strong>通常是由<strong>数据存储库本身将活动记录到文件系统中</strong>。但是，<strong>日志记录通常会因为</strong><span style="color: rgb(61, 167, 66);"><strong>性能下降</strong></span><strong>和</strong><span style="color: rgb(61, 167, 66);"><strong>PII泄密风险</strong></span><strong>等原因而关闭：</strong></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;">性能下降</strong>。在MySQL和PostgreSQL数据库中，当打开查询日志记录时，由于关键查询执行路径中产生的额外I/O，<strong>QPS(每秒查询数)通常会下降25-30%</strong>；</section></li><li><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><strong style="margin: 0px;padding: 0px;">PII泄密的风险</strong>。被记录的查询/请求日志，并没有经过对PII信息的隐私处理。这必然导致安全问题。</section></li></ul><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">3.2）DBaaS(数据库即服务)的可见性不足<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span></strong></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>DBaaS中的指标主要有两个来源，但都存在不足</strong>：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>一是粗粒度的DBaaS指标</strong>。这些是由DBaaS引擎自身发布的聚合指标，比如说每秒连接次数、每秒SELECT/UPDATE/INSERT<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">次</span>数、<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">每秒慢速查询<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">次</span></span>数。但它们都是<span style="color: rgb(61, 167, 66);"><strong>粗粒度</strong></span>的，<strong>无法对应</strong>到与DBaaS交互的特定用户或服务；</p></li><li><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;"><strong>二是汇总的云提供商指标</strong>。但这些指标也<strong>无法被有效映射和归因</strong>。<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">例如，AWS Cloudwatch发布了与DBaaS引擎的网络I/O活动相对应的字节数和吞吐量。然而，</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;color: rgb(0, 0, 0);display: inline !important;">它无法识别出某个表中的多少行或者某个集合中的多少文档，对应于网络层观察到的字节数量</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">。也不可能将这些指标的观察值，归因于特定用户或服务。</span></p></li></ul><p style="margin-top: 8px;"><strong>3.3）<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">传统数据库部署的<strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">可见性不足</strong></strong></strong></p><p style="margin-top: 8px;"><strong>传统的数据库部署的确</strong><span style="color: rgb(61, 167, 66);"><strong>增加了一些可见性</strong></span>，如下所示。但由于<strong>性能影响</strong>或<strong>存储成本</strong>，<strong>这些日志通常会被禁用</strong>。</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong>服务帐户</strong>：用户通常使用<strong>BI(商业智能)工具</strong>或<strong>应用程序</strong>登录数据库，而BI工具和应用程序将使用共享型<strong>服务帐户</strong>来查询数据库。也就是说，<strong>真实</strong><strong>用户的身份无法记录在数据库日志中</strong>。</section></li><li><section style="margin-top: 8px;"><strong>用户活动</strong>：身份认证日志可以突出显示身份认证失败时间，包括事件的日期和时间。但是，这类日志<strong>不包括上下文数据</strong>，包括执行的查询或调用者的源IP。</section></li><li><section style="margin-top: 8px;"><strong>查询活动</strong>：这类日志通常用于数据库调优，包含性能细节，包括查询计划和执行时间。</section></li><li><section style="margin-top: 8px;"><strong>系统健康状况</strong>：关于数据库健康状况的聚合指标，包括使用的内存和存储、上次运行性能调优的时间，以及硬件或损坏问题。</section></li></ul><section style="margin-top: 8px;"><strong>3.4）增强型数据库原生控制方法的不足</strong></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;">增强数据访问控制的一种常见方法，是<strong>将数据存储与IAM产品进行集成</strong>，从而为数据访问增强用户身份识别能力。</section></li><li><section style="margin-top: 8px;">但是，这种集成在安全和监管方面留下了空白，因为<strong>它们没有将数据库原生访问控制的全部功能扩展到经过SSO身份认证的用户，也没有提供可以扩展的访问策略工具</strong>。</section></li></ul><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;clear: both;min-height: 1em;">总而言之，数据存储原生控制在很多时候都<strong><span style="color: rgb(61, 167, 66);">靠不住</span></strong>。所以，<strong>数据访问代理</strong>方法才被广泛采用。</p><p style="margin-top: 8px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">数据访问代理方法</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><br style="margin: 0px;padding: 0px;"/></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><strong><span style="font-size: 17px;">1）代理和<strong>数据库代理</strong></span></strong><br/></p><p style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;font-size: 17px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: PingFangSC-light;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 2px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></span></strong></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><strong style="font-size: 17px;">代理</strong><span style="font-size: 17px;">是位于客户端和服务器之间的拦截服务。</span><span style="font-size: 17px;">当代理靠近客户端部署时，称为</span><strong style="font-size: 17px;">正向代理</strong><span style="font-size: 17px;">。</span><span style="font-size: 17px;">当代理部署在离服务器更近的地方，使得客户端不知道服务器的来源时，它被称为</span><strong style="font-size: 17px;">反向代理</strong><span style="font-size: 17px;">。</span><br/></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><strong style="font-size: 17px;">数据库代理</strong><span style="font-size: 17px;">（ProxySQL、MaxScale等）基本上是一种</span><span style="color: rgb(61, 167, 66);"><strong style="font-size: 17px;">反向代理</strong></span><span style="font-size: 17px;">，旨在为数据库、键值存储、消息队列提供安全性、可伸缩性、高可用性等优势。</span></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><span style="font-size: 17px;"><img class="rich_pages wxw-img" data-ratio="0.5308219178082192" data-w="1460" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ae3287dc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPN5dIErwcGFiabicB9VibSIiaNWSukjRQOcGVy8LTH0OkT0Rk3WBQibQkGo9v7ibqUItqPHb6lnFYrzybiaQ%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><span style="font-size: 17px;">图1-数据库代理</span></p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: center;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><span style="font-size: 17px;"><br/></span></p><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><span style="font-size: 17px;"></span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: normal;">2）SQL无感知</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;letter-spacing: normal;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 34px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span><strong>数据库</strong>代理</strong></section><section style="margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong>在高度分布式的数据存储库（如MongoDB和Cassandra）流行之前，数据库代理通过为后端数据存储库提供<span style="color: rgb(61, 167, 66);"><strong>连接池</strong></span>，来实现扩展性和高<span style="color: rgb(0, 0, 0);">性能</span>。通过将请求路由到健康的数据后端，来确保高可用性，并减少故障转移时间。</section><section style="margin-top: 8px;">此类数据库代理通常被称为<strong>L4层</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">代理</span>或<strong>SQL无感知代理</strong>，包括HAProxy、Nginx和类似工具。</section><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">3）SQL感知数据库代理</strong></section><section style="margin-top: 8px;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong>随着应用程序迁移到云端，数据量猛增，现代数据存储库开始提供可扩展性和高可用性功能，使用分布式<span style="color: rgb(61, 167, 66);"><strong>Coordinator-Worker</strong></span><strong>（协调器-工作节点）架构</strong>的数据分片和复制。</section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.5082508250825083" data-w="909" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=429a7d50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNDWm93RYqf2KAI9RDYRvQiam0Jf5NdYKmSWFs50bytVVNp2OQWRNI30BaHvRQJ4Zl49PJqDuCxvZA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图2-Coordinator-Worker架构</section><section style="margin-top: 8px;">为了<strong>保护应用程序逻辑免受底层拓扑变化的影响</strong>，ProxySQL和MaxScale等 <strong>SQL感知数据库代理</strong>开始受到关注。</section><section style="margin-top: 8px;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">SQL感知代理</span>可以执行这类任务：通过将<strong><span style="color: rgb(0, 0, 0);">读查询</span></strong>定向到<span style="color: rgb(255, 0, 0);"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Worker</strong></span>并将<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">写</strong></span><strong>查询</strong>定向到<span style="color: rgb(255, 0, 0);"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Coordinator</strong></span>中的<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">master</span>，来执行<strong>SQL读</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="margin: 0px;padding: 0px;color: rgb(0, 0, 0);">查询</span></strong></span><strong>/写查询的路由</strong>。</section><section style="margin-top: 8px;">SQL感知代理也用于这些场景：需要在SQL层操作以<strong>缓存SQL查询的</strong><span style="color: rgb(0, 0, 0);"><strong>响应</strong></span>，以提高性能；或者<strong>重写和阻断某些SQL查询</strong>，以增加安全性。</section><section style="margin-top: 8px;">事实上，目前主流的<span style="color: rgb(61, 167, 66);"><strong>数据访问平台</strong></span>都采用了感知型数据库代理的方式。这也是当前最被看好的数据访问控制方法。<br/></section><section style="margin-top: 8px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.755420054200542" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;color: rgb(51, 51, 51);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;" data-type="png" data-w="1476" src="https://wechat2rss.xlab.app/img-proxy/?k=05143e76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOFbu8GQunvVyiaZjsfUABx59PkicXeSaQc77MRnP6DlppBF1NVOnbXSEST4oKa8ClibZsjSNPCJahNQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 8px;text-align: center;">图3-基于数据库代理模式的数据访问平台</section><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="margin: 0px;padding: 0px;white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;padding: 0px;display: inline-block;"><section style="margin: 0px;padding: 0px;border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="margin: 0px;padding: 0px;width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin: 0px 0px 0.25em;padding: 0px 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="margin: 0px;padding: 0px;max-width: 100%;min-height: 1em;"><span style="margin: 0px;padding: 0px;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-align: center;"><strong style="margin: 0px;padding: 0px;"><span style="margin: 0px;padding: 0px;text-indent: 34px;"><strong style="margin: 0px;padding: 0px;text-align: left;">数据层边车方法</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="margin: 0px;padding: 0px;max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br style="margin: 0px;padding: 0px;"/></section></section></section></section><p style="margin: 0px;padding: 0px;clear: both;min-height: 1em;"><br style="margin: 0px;padding: 0px;"/></p><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;"><strong>1）传统代理无法适应云原生环境</strong></section><section style="margin: 8px 0px 0px;padding: 0px;clear: both;min-height: 1em;">随着<strong>容器技术</strong>尤其是Docker的成熟，以微服务为可组合单元的<strong>面向服务架构（SOA）</strong>开始受到广泛欢迎。<strong>云原生应用程序</strong>开始使用微服务作为它们的构建模块，从而将自身用于持续集成和持续部署的DevOps方法。<br/></section><section style="margin-top: 8px;">虽然基于微服务的新架构带来了许多好处，但它们也暴露了挑战，特别是在安全和流量管理方面：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;">这些分散的微服务之间的通信，导致<strong>东西向</strong>流量激增；</section></li><li><section style="margin-top: 8px;">却没有可以强制执行安全规则的<strong>明确</strong><strong>边界</strong>；</section></li><li><section style="margin-top: 8px;">也没有可以执行流量管理的<strong>单一入口/出口点</strong>。</section></li></ul><section style="margin-top: 8px;">因此，<span style="color: rgb(61, 167, 66);"><strong>在应用程序和数据存储库（数据库或数据仓库）之间部署代理的传统模型，在云原生的新世界中不再适用</strong></span>。</section><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><strong>2）云原生世界需要数据层边车</strong><br/></section><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">在云原生世界中部署代理的<strong style="margin: 0px;padding: 0px;">思路</strong>是<span style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">数据层边车（Sidecar<strong style="margin: 0px;padding: 0px;">）</strong></strong></span>，即采用<strong>边车模式部署</strong>的<strong>无状态拦截服务</strong>。</p><p style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"></span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">在云原生应用程序</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">部署</span><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">架构中，</span><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">数据层边车本质上充当应用程序和数据之间的断路器</strong><span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">，以保护数据存储库。</span></p><p style="margin-top: 8px;"><strong>数据层边车</strong><strong>诞生于云中</strong><strong><span style="font-weight: 400;"></span></strong><strong><span style="font-weight: 400;"></span><span style="font-weight: 400;">，</span></strong>可以快速部署到客户环境中，并实时拦截对任何类型数据存储库（数据库、数据管道、数据仓库等）的所有请求，而不会影响性能和可扩展性。所有的集成和配置，都可以从<strong>统一控制平面</strong>进行集中管理。<br/></p><p style="margin-top: 8px;">由于数据层边车便于使用Kubernetes等<strong>服务编排工具</strong>进行部署，因此企业可以确保其所有存储库的数据保护始终处于<strong>开启状态</strong>。</p><section style="margin-top: 8px;"><strong>虽然数据层边车仍然发挥</strong><span style="color: rgb(61, 167, 66);"><strong>代理的作用</strong></span><strong>，但它的架构是为云原生架构而设计的</strong>：</section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.4090447154471545" style="margin: 0px;padding: 0px;max-width: 100%;height: auto !important;vertical-align: bottom;" data-type="png" data-w="1968" src="https://wechat2rss.xlab.app/img-proxy/?k=535d5f0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNDWm93RYqf2KAI9RDYRvQiaRJh4yDf1Htq6DAGQmYsyFUfPffTlzWMnprU7VSYl1ZpR5gvKrZUrNQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin: 8px 0px 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;text-align: center;">图4-拦截方式对比：传统代理 vs. 数据层边车</section><section style="margin-top: 8px;">如上图所示，<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">数据层边车可以采取</span><span style="color: rgb(61, 167, 66);"><strong>无状态</strong></span>方式运行，从而支持横向扩展和高可用性。</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;">传统的应用程序代理，需要管理查询客户端的<strong>会话状态</strong>，以帮助旧数据库架构应付繁重的工作压力。</section></li><li><section style="margin-top: 8px;">而如今，<strong>数据存储库能够自己管理数据层连接，因此数据层边车可以无状态运行</strong>。于是，可以部署<strong>多个边车</strong>，来保护单个数据存储库。</section></li></ul><section style="margin-top: 8px;"><br/></section><section style="margin-top: 8px;"><strong>3）数据层边车 vs. 数据库代理</strong><br/></section><p style="margin-top: 8px;">数据层边车与数据库代理相比，具有很多明显的优势：<strong><strong style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"></strong></strong></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 8px;"><strong style="">数据架构的先进性</strong>：数据层边车支持现代<span style="color: rgb(61, 167, 66);"><strong style="">数据网格架构</strong></span>；而数据库代理采用<strong style="">中心辐射架构</strong><span style="">，来自微服务的流量被迫先到达代理，然后才被发送到目标。</span><br/></section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;">云编排平台的可用性</strong>：数据层边车使用<span style="color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">云编排平台</strong></span>（如Kubernetes）部署；而数据库代理通常使用未集成到云编排平台。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong>流量控制能力</strong>：数据层边车支持<span style="color: rgb(61, 167, 66);"><strong>全方向</strong></span>流量控制，即包括南北向和东西向；而<strong><span style="font-weight: 400;">数据库代理</span></strong><strong><span style="font-weight: 400;">仅支持</span>南北向</strong>。</section></li><li><section style="margin-top: 8px;"><strong>可观测能力</strong><strong><span style="font-weight: 400;">：数据层边车与</span></strong><span style="color: rgb(61, 167, 66);"><strong>可观测性技术栈</strong></span><strong><span style="font-weight: 400;">（如ELK、Prometheus等）高度集成，具有丰富的遥测数据；而数据库代理只有基本的日志数据。</span></strong></section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;">微服务环境的适应性</strong>：数据层边车与<span style="color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">基础设施模板工具</strong></span>（如Terraform、Cloudformation等）一起使用；而数据库代理不适合高度分布式的微服务环境。</section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;">DevOps集成</strong>：数据层边车采取<strong style="margin: 0px;padding: 0px;">API优先原则</strong>，与<span style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">DevOps工具</strong></span>（如Prometheus、Grafana等）集成，用于日志记录、监测、可视化、CI/CD；而数据库代理缺少与DevOps工具的集成。<br style="margin: 0px;padding: 0px;"/></section></li><li style="margin: 0px;padding: 0px;clear: both;"><section style="margin: 8px 0px 0px;padding: 0px;"><strong style="margin: 0px;padding: 0px;">持续部署</strong>：<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">数据层边车</span>通过与<span style="margin: 0px;padding: 0px;color: rgb(61, 167, 66);"><strong style="margin: 0px;padding: 0px;">CI/CD工具</strong></span>（如Jenkins X、Spinnaker等）的集成，实现持续部署；<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">而数据库代理</span>不支持CI/CD。</section></li><li><section style="margin-top: 8px;"><strong>网络延迟</strong>：数据层边车采用<strong>无状态</strong>的断路器设计，使得去往数据存储库的流量延迟可以<strong>忽略不计</strong>；而数据库代理在服务和数据存储库之间引入额外控制点，导致<strong>不可忽略</strong>的网络延迟。<br/></section></li><li><section style="margin-top: 8px;"><strong>身份保护</strong>：<span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">数据层</span><span style="margin: 0px;padding: 0px;color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">边车</span>内置了使用<strong>mTLS</strong>的身份保护，提供了<strong>原生</strong>的身份认证和授权能力；<span style="color: rgb(51, 51, 51);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;">而数据库代理</span>缺少对连接服务进行身份认证和授权的原生支持。</section></li></ul><p><br/></p><p><span style="white-space:pre-wrap;"></span></p><section>（本篇完）</section>



<p><a href="2247494737">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=75a9477d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494737%26idx%3D1%26sn%3D503149c7dfc7b91d6bd16c6de6b11721%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 04 Jul 2022 06:36:00 +0800</pubDate>
    </item>
    <item>
      <title>数据治理的三种共享范式</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494702&amp;idx=1&amp;sn=083162425dc4d334e4ed5e3e9b769b51</link>
      <description>共享，还是独享</description>
      <content:encoded><![CDATA[<p>
原创 <span>启承 &amp;amp; 柯学</span> <span>2022-06-01 06:18</span> <span style="display: inline-block;">北京</span>
</p>

<p>共享，还是独享</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b6eb5a6a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPOyfIw726ibzunnbFF9u4ZgicU6CQzbneono3GDoxnymrNJwsuYgAtO15BPicfJicVEKQzNyFyeN3ZOIw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<span style="color: rgb(0, 0, 0);"><strong>30</strong><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong>数据共享范式</strong>的演变，从<strong style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">过度授权</strong>的“<span style="color: rgb(61, 167, 66);"><strong>默认知道</strong></span>”（Default-to-Know），到<strong>默认不共享</strong>的“<span style="color: rgb(61, 167, 66);"><strong>需要知道</strong></span>”<span style="text-align: left;">（ Need-to-know），再</span>到<strong style="text-align: left;white-space: normal;">默认共享</strong>的“<span style="color: rgb(61, 167, 66);"><strong>需要共享</strong></span>”<span style="text-align: left;">（ Need-to-share）</span>。这些范式，本质上是在<strong>数据价值</strong>和<strong>数据风险</strong>之间进行取舍和平衡。</section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><span style="text-align: left;">众所周知，安全法规和最佳实践似乎经常要求组织将<strong>数据锁定</strong>，从而限制“</span><span style="text-align: left;color: rgb(61, 167, 66);"><strong>需要知道</strong></span><span style="text-align: left;"><span style="text-align: left;">”</span>的员工的访问。然而，数据只有与需要它的人共享时，才有价值。但是，<span style="text-align: left;">数据</span>的更广泛共享，既需要秉持“</span><span style="text-align: left;color: rgb(61, 167, 66);"><strong>需要共享</strong></span><span style="text-align: left;">”的原则，又需要采用创新的数据安全方法，如<strong><span style="text-align: left;">数据安全治理框架</span></strong>和<strong>数据安全平台</strong>。</span></section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong style="text-align: left;white-space: normal;">数据共享范式将影响许多数据驱动型组织</strong><span style="text-align: left;">。</span>根据Gartner的观点，到2025年，30%的Gartner客户将使用“<span style="color: rgb(61, 167, 66);"><strong>需要共享</strong></span>”方法，而非传统的“<span style="color: rgb(61, 167, 66);"><strong>需要知道</strong></span>”方法，来保护他们的数据。</section><section style="white-space: normal;text-align: left;margin-top: 0.5em;">组织应该审视：其<span style="text-align: left;">数据安全策略和数据安全治理框架，是否还</span><span style="text-align: left;">停留在石器时代。</span></section></section></section></section></section></section><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section style="white-space: normal;">1.杰出数据共享的好处<br/></section><p>2.传统数据共享的问题</p><p>3.从“默认知道”到“需要知道”</p><p>4.从“需要知道”到“需要共享”</p><p>5.DataSecOps方法</p><p style="margin-top: 16px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">杰出数据共享的好处</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p><br/></p><p style="margin-top: 8px;"><span style="color: rgb(61, 167, 66);"><strong>杰出数据共享</strong></span>意味着，大量用户可以快速、轻松地<strong>访问数据</strong>，以便他们可以<strong>分析数据</strong>并<strong>使用数据</strong>，来改善各种职能（包括客户服务、留存、支持、运营、营销、销售等）的<strong>业务成果</strong>。</p><p style="margin-top: 8px;">杰出数据共享蕴含了<span style="color: rgb(61, 167, 66);"><strong>数据民主化</strong></span>的理念，<strong>使组织内的尽可能多的人能够访问数据，并将其转化为有意义的</strong><span style="color: rgb(61, 167, 66);"><strong>业务价值</strong></span>。</p><p style="margin-top: 8px;">杰出数据共享有以下主要好处：</p><ul type="disc" class="list-paddingleft-1"><li><p style="margin-top: 16px;">当组织中的许多<strong>数据消费者</strong>使用数据时，他们能够快速将数据转化为价值，组织将获得较高的<strong>数据投资回报率</strong>。</p></li><li><p style="margin-top: 16px;">当组织拥有杰出数据共享时，数据产品/项目的上市时间和实现价值的<strong>时间就会缩短</strong>。这可能会对组织的业务结果产生重大影响。</p></li><li><p style="margin-top: 16px;">当组织的数据共享运行良好时，组织可以减少数据的瓶颈和排队时间。这使组织的用户（如数据科学家、业务分析师、工程师）更加快乐，并使数据工程和数据治理等团队更加专注于他们的核心职责，而不是手动管理和处理数据访问请求。</p></li></ul><p style="margin-top: 16px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">传统数据共享的问题</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;"><br/></p><p style="margin-top: 16px;"><strong>数据治理</strong>是指<strong>监督数据管理</strong>的政策和流程。数据治理需要保证数据安全可靠。</p><p style="margin-top: 16px;"><strong>传统上，在数据共享方面，组织倾向于“</strong><span style="color: rgb(61, 167, 66);"><strong>选择加入</strong></span><strong>”（opt-in）方法。这意味着</strong><span style="color: rgb(61, 167, 66);"><strong>默认情况下数据所有者不与组织的其他成员共享数据</strong></span>。</p><p style="margin-top: 16px;"><strong>评估过程需要时间</strong>。当有其他成员专门请求数据共享时，<strong>数据所有者</strong>通常会评估共享数据的好处和风险：<strong>好处</strong>主要是不同类型的<strong>业务成果</strong>，例如改进的营销、客户服务、运营；<strong>风险</strong>主要是合规和安全风险（例如不符合监管要求或数据泄露）。而这个评估过程需要时间。</p><p style="margin-top: 16px;"><strong>技术启用还需要时间</strong>。从数据所有者批准对共享数据集的访问开始，通常还需要额外时间由<strong>数据团队</strong>（如数据工程、平台和共享数据服务等）在技术上启用共享，才能真正与<strong>数据消费者</strong>（如数据科学家、业务分析师、工程师等）共享数据。 </p><p style="margin-top: 16px;white-space: normal;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">从“默认知道”到“需要知道”</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;"><br/></p><p style="margin-top: 16px;"><strong>“<strong style="white-space: normal;">默认知道</strong>”访问模式的后果</strong>。很多企业，特别是处于<strong>高速增长模式</strong>时，都采用“<strong>默认知道</strong>”的数据访问模式。这意味着以<strong>过度授权（甚至是<strong style="white-space: normal;">不受控制</strong>）</strong>的方式访问数据。这种过度授权通常会在安全和合规风险方面产生问题。</p><p style="margin-top: 16px;"><strong>总有一天，企业想要缩小这些授权</strong>。而缩小这些授权通常是个很费劲的过程。因为公司不得不设置新的安全控制，创建新的流程，应用新的安全策略。而那些之前已经习惯于免费访问所有数据的用户，将只能基于其角色和责任获得有限的访问权限。而这个过程必然是痛苦的，比如：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 8px;">生产和分析环境中不断变化的安全控制，会带来运营风险和成本。</p></li><li><p style="margin-top: 8px;">这个过程需要被具有不同目标的多个不同团队所理解、接受、执行。</p></li><li><p style="margin-top: 8px;">这个过程通常很难获得支持，尤其是当业务价值并不总是增长时。一般来说，如果公司不满足某些数据访问控制要求，它们将会达到增长上限。</p></li></ul><p style="margin-top: 16px;"><strong>“<strong style="white-space: normal;">需要知道</strong>”访问模式</strong>。企业的下一步自然是从“默认知道”转变为“需要知道”。这意味着，在转变之前，所有（或大多数）数据消费者都可以访问数据存储中的所有（或大多数）数据；而现在，基于他们在组织中的<strong>角色</strong>（如客户成功、工程师、营销）和具体<strong>职责</strong>，他们对数据的访问将受到限制。其他的例子还包括仅限特定团队访问敏感数据、数据匿名化和脱敏，以及应用数据本地化策略。</p><p style="margin-top: 16px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">从“需要知道”到“需要共享”</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;"><br/></p><p style="margin-top: 16px;">已经看到并且可以预期，已经处于“需要知道”心态的组织，正在意识到，重点应该放在允许组织中更多的数据可访问性上，并保持<strong>共享优先</strong>的心态。</p><p style="margin-top: 16px;">为了更好地向“需要共享”范式转变，组织需要改变思维方式和行为：   </p><p style="margin-top: 16px;"><strong>1）从风险厌恶到风险调整</strong></p><p style="margin-top: 16px;"><strong><span style="color: rgb(61, 167, 66);"><strong>风险厌恶</strong></span><strong style="white-space: normal;">（Risk-Averse）</strong></strong><strong>策略</strong>。许多组织采用风险厌恶的策略，即先试图<strong>缓解</strong><strong>所有风险</strong>，然后才接受数据共享请求。<br/></p><p style="margin-top: 16px;"><strong style="white-space: normal;"><span style="color: rgb(61, 167, 66);"><strong>风险调整</strong></span><strong style="white-space: normal;">（Risk-Adjusted）</strong></strong><strong>策略</strong>。但更优的策略是风险调整，即组织<strong>直接</strong><strong>从<strong style="color: rgb(61, 167, 66);white-space: normal;">数据</strong></strong><span style="color: rgb(61, 167, 66);"><strong>被</strong><strong>共享和处理的位置</strong></span><strong>开始</strong>，着手缓解风险。</p><p style="margin-top: 16px;"><strong style="white-space: normal;">风险调整</strong><strong style="white-space: normal;">策略</strong><strong>的一个例子</strong>是拥有一个连续的<strong>匿名化层</strong>，以确保共享的数据被匿名化或脱敏到所需的程度。具有<strong>基于角色的脱敏</strong>非常重要，这样客户成功团队就可以访问客户的出生日期（即月份和日期），这样他们就<strong>可以祝他们生日快乐，但无法访问出生日期字段的年份</strong>；而其他用户则根本无法访问出生日期的任何部分，因为他们的工作不需要。   </p><p style="margin-top: 16px;"><strong>2）从选择加入到选择退出数据共享</strong></p><p style="margin-top: 16px;"><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">选择加入</strong></span><strong style="white-space: normal;">（Opt-In）数据共享</strong>：<strong style="white-space: normal;"></strong>意味着数据所有者<span style="color: rgb(61, 167, 66);"><strong>默认不共享</strong></span><strong>数据</strong>，只是<strong><span style="color: rgb(61, 167, 66);">有选择地共享</span></strong><strong>某些数据</strong>。这种方式很容易产生<strong>数据孤岛</strong>。</p><p style="margin-top: 16px;"><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">选择退出</strong></span><strong style="white-space: normal;">（Opt-Out）数据共享</strong>：意味着数据所有者<span style="color: rgb(61, 167, 66);"><strong>默认共享</strong></span><strong>数据</strong>，只是<span style="color: rgb(61, 167, 66);"><strong>有选择地不共享</strong></span><strong>某些数据</strong>。</p><p style="margin-top: 16px;"><strong>共享方式转变</strong>。从“选择加入”转变为“选择退出”数据共享，意味着组织中的<strong>数据默认都是共享</strong>的，而数据所有者需要决策的是哪些数据不能共享。</p><p style="margin-top: 16px;"><strong>数据访问控制</strong>。更加重要的是，数据默认共享隐含了数据访问控制的要求。也就是说，数据所有者以及其他数据干系人（数据治理、数据安全、数据隐私等团队）可以并且应该对要共享的数据（尤其是敏感数据）进行访问限制。<br/></p><p style="margin-top: 16px;"><strong>3）从数据所有者手中</strong><span style="color: rgb(61, 167, 66);"><strong>夺走（部分）权力</strong></span></p><p style="margin-top: 16px;"><strong style="white-space: normal;">数据所有者拥有过度</strong><span style="color: rgb(0, 0, 0);"><strong>权力</strong></span>。传统上，数据所有者会收到组织中其他团队的共享请求，有时会在与他人协商后决定是否共享数据。他们大多是根据风险与价值的衡量，来做出这个决定。而问题在于，<span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">数据所有者通常对风险和价值的看法存在偏见</strong></span><strong style="white-space: normal;">。</strong>因为数据所有者和数据创建者通常对共享数据所涉及的风险持有狭隘的观点，而忽视了数据共享所带来的价值。</p><p style="margin-top: 16px;"><strong>组织需要剥夺数据所有者的部分权力</strong>。剥夺权力的最佳方式，就是采用上面提<span style="color: rgb(0, 0, 0);">到的“<strong>选择退出</strong>”模式，即数据默认都是共享的，而</span><strong style="white-space: normal;">数据所有者</strong>只能选择那些不能共享的特定数据集。</p><p style="margin-top: 16px;"><strong>4）清晰透明的安全、治理、隐私策略</strong></p><p style="margin-top: 16px;">前面已经提到，在共享数据时，如果不采取必要的控制措施来避免风险，就不可能实现“需要共享”的目标。</p><p style="margin-top: 16px;">要实现这一点，组织需要制定非常清晰的数据共享“参与规则”。这意味着组织需要清楚地了解：</p><ul type="disc" class="list-paddingleft-1"><li><p style="margin-top: 8px;"><strong>持续了解敏感数据的位置</strong>。否则，数据暴露风险可能会压倒数据民主化的愿望。</p></li><li><p style="margin-top: 8px;"><strong>具备敏捷访问控制的能力</strong>。这意味着，即使数据集在整个组织中共享，也只有某些特定组才能访问PII（个人识别信息）。这通常通过动态数据脱敏等方法来实现。</p></li><li><p style="margin-top: 8px;"><strong>有一个“委员会”（或团队）</strong>，可以针对数据共享的限制性做出快速决策，并解决冲突。</p></li><li><p style="margin-top: 8px;"><strong>培训所有数据干系人</strong>（在许多数据驱动型组织中，他们可能是组织的重要组成部分），在数据隐私、数据安全、数据治理等方面。</p></li></ul><p style="margin-top: 16px;"> </p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">DataSecOps方法</strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;"><br/></p><p style="margin-top: 16px;">在组织内转向更加开放的数据共享策略，非常符合<strong>DataSecOps</strong>（数据安全运营）理念。换句话说，一个组织要想处于数据民主化的态势，就不得不采用DataSecOps原则，如将安全性嵌入在流程本身中，否则，将无法以自动化方式应用访问策略来获得即时数据访问。 </p><p style="margin-top: 16px;"><strong>“需要共享”</strong>是所有组织处理其数据的恰当方式吗？不，这种方法可能被视为“<strong>纯粹数据民主化</strong>”。<strong>它适用于在DataSecOps方面达到成熟或部分成熟水平的组织</strong>。<br/></p><p style="margin-top: 16px;">然而，在<strong>数据优先经济</strong>中，一个高阶的“需要共享”型组织，必然会对“默认知道”和“需要知道”型组织形成“不公平的优势”。</p><p style="margin-top: 16px;">而一个好的<strong>数据安全平台</strong>，也是一个<strong>DataSecOps平台</strong>，无论组织采取“默认知道”、“需要知道”、“需要共享”范式的哪一种，都可以帮助组织增强数据访问控制并加速数据价值实现。 </p><p style="margin-top: 16px;"><br/></p><section style="margin-top: 0.5em;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span><span style="text-align: center;"></span></section>



<p><a href="2247494702">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6ed1a51c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494702%26idx%3D1%26sn%3D083162425dc4d334e4ed5e3e9b769b51%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 01 Jun 2022 06:18:00 +0800</pubDate>
    </item>
    <item>
      <title>数据治理的三本数据秘籍</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494693&amp;idx=1&amp;sn=d871fdeffad85c6c0e1bc5f8faf5ae41</link>
      <description>秘籍在手，数据不愁</description>
      <content:encoded><![CDATA[<p>
原创 <span>一帆 &amp;amp; 柯学</span> <span>2022-05-11 06:09</span> <span style="display: inline-block;">北京</span>
</p>

<p>秘籍在手，数据不愁</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=095fc5fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPPEfJhjk8O6owJTeV80GJdhFrFlMn5pyvicOveryPRjt9qVcQBWic2opK0Pvia2rgAgU7cqVDynyL3iaA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<span style="color: rgb(0, 0, 0);"><strong>35</strong><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong><strong style="text-align: left;white-space: normal;"><strong style="text-align: left;white-space: normal;">数据目录</strong></strong>、<strong style="text-align: left;white-space: normal;">数据清单</strong>、数据字典是良好数据治理活动的组成部分</strong>。它们被经常混用，但它们并不相同。</section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据目录</strong>汇总了组织中数据资产的整体概况；<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据清单</strong>详细说明了组织中可用的所有<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据集</strong>，并显示所有相关<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">元数据</strong>；<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">数据字典</strong>定义了这些数据集的<span style="outline: 0px;max-width: 100%;color: rgb(61, 167, 66);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">规则</strong></span>，指示了它们的格式、形状、schema。</section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong>这些数据秘籍的最大挑战是保持其最新</strong>。由于数据<span style="color: rgb(0, 0, 0);">采集</span>管道的速度和数量是天文数字，因此需要自动化和敏捷的协议来更新它们。</section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><strong><span style="text-align: left;">拥有这些数据秘籍</span><span style="text-align: left;">并保持最新</span></strong><span style="text-align: left;">，</span><span style="text-align: left;">可确保</span><span style="text-align: left;">高效的数据交互，</span><span style="text-align: left;">使企业团队</span><span style="text-align: left;">能够</span><span style="text-align: left;">简化</span><span style="text-align: left;">其</span><span style="text-align: left;">数据</span><span style="text-align: left;">操作并</span><span style="text-align: left;">获</span><span style="text-align: left;">取</span><span style="text-align: left;">有价值的</span><span style="text-align: left;">数据</span><span style="text-align: left;">洞察。</span></section><section style="white-space: normal;text-align: left;margin-top: 0.5em;"><span style="color: rgb(61, 167, 66);"><strong style="text-align: left;white-space: normal;">数据清单</strong></span>是执行<strong>数据清点/盘点</strong>的基础。一个高价值的<strong>数据安全平台</strong>，应该能够自动化<span style="text-align: left;">维护一个持续更新的</span><strong style="text-align: left;white-space: normal;">数据清单</strong>，其中<span style="text-align: left;">包括敏感数据的</span><span style="text-align: left;color: rgb(0, 0, 0);">分类分级</span>。</section></section></section></section></section></section><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section style="white-space: normal;">1.数据治理中的三本秘籍</section><p style="text-indent: 2em;"><span style="text-indent: 34px;">1）</span><span style="text-indent: 34px;">数据目录（Data Catalog）？</span></p><p style="text-indent: 2em;">2）数据清单（Data Inventory）？<br/></p><section style="white-space: normal;text-indent: 2em;">3）数据字典（Data Dictionary）<span style="text-indent: 34px;">？</span></section><p style="white-space: normal;">2.<span style="text-indent: 34px;">为何</span>需要这些数据秘籍</p><section style="white-space: normal;text-indent: 2em;"><span style="text-indent: 2em;">1）</span><span style="text-indent: 34px;">为何需要</span><span style="text-indent: 2em;">数据目录？</span></section><section style="white-space: normal;text-indent: 2em;">2）为何需要数据清单？</section><section style="text-indent: 2em;">3）为何需要数据字典？</section><p style="white-space: normal;">3.数据秘籍之间的区别</p><section style="white-space: normal;text-indent: 2em;"><span style="text-indent: 2em;">1）</span>数据目录 <span style="text-indent: 2em;">vs. </span>数据清单<span style="text-indent: 2em;"></span><br/></section><section style="white-space: normal;text-indent: 2em;"><span style="text-indent: 34px;"></span></section><section style="white-space: normal;text-indent: 2em;"><span style="text-indent: 34px;">2）数据目录 vs. 数据字典</span></section><section style="white-space: normal;text-indent: 2em;">3）数据清单 vs. 数据字典<br/></section><p style="white-space: normal;">4.创建数据秘籍的关键因素<br/></p><section style="text-indent: 2em;">1）重点关注敏感数据</section><section style="text-indent: 2em;">2）持续敏感数据发现</section><section style="text-indent: 2em;">3）确保对半结构化数据进行<span style="color: rgb(0, 0, 0);">分类分级</span>和更新</section><section style="white-space: normal;margin-top: 2em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="white-space: normal;">数据治理中的三本秘籍</strong></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p><br/></p><section style="margin-top: 0.5em;"><strong>1）数据目录（Data Catalog）</strong></section><section style="margin-top: 0.5em;">数据目录是企业用来管理其数据的集中式<strong>元数据存储库</strong>。其中概述了企业<strong>数据资源的组织、使用、管理</strong>的信息。该目录支持数据工程、分析操作、科学的<span style="color: rgb(0, 0, 0);">功能</span>。</section><section style="margin-top: 0.5em;">数据目录的目标是使数据管理变得简单有效，共享有关收集和存储在组织中的数据的知识和信息。它概述了各种管道中的数据流，并提供数据景观的<strong style="white-space: normal;">鸟瞰图</strong>。</section><section style="margin-top: 0.5em;"><strong>数据目录通常与它们所引用的数据集</strong><span style="color: rgb(61, 167, 66);"><strong>分开存储</strong></span><strong>在数据仓库或数据湖中</strong>。<br/></section><section style="margin-top: 0.5em;">数据目录的建立，需要遵循以下<strong>五个步骤</strong>：</section><ol class="list-paddingleft-1" style="width: 577.417px;"><li><p><strong>数据获取</strong>：首先确定哪些元数据是相关的，找到这些相关数据所在的位置和存储的形式，确定如何捕获它们。通过了解数据的形状、结构、语义，来发展数据目录的形状和结构。尽量自动更新数据目录，<strong style="white-space: normal;">几乎所有的</strong><span style="color: rgb(61, 167, 66);"><strong>数据库和数据存储</strong></span><strong style="white-space: normal;">都有工具，可以帮助您以所需的形状和语义</strong><span style="color: rgb(61, 167, 66);"><strong>提取元数据</strong></span>。通过<strong style="white-space: normal;">数据沿袭</strong>，了解数据的来源和去向，<strong style="white-space: normal;">为数据用户提供上下文</strong>。数据目录应支持各种数据类型，包括表和流数据。</p></li><li><p><strong>分配数据所有者</strong>：捕获数据后，组织必须分配对该数据的所有权。赋予某人确保数据和文档完整和准确的责任，并为需要额外信息的数据用户提供了一个联系人。<strong style="white-space: normal;">最重要的数据所有者，是</strong><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">数据管理员</strong></span><strong style="white-space: normal;">和</strong><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">技术所有者</strong></span>。<strong style="white-space: normal;">数据管理员</strong>管理和解决与业务相关的查询；而<strong style="white-space: normal;">技术所有者</strong>负责解决技术问题。</p></li><li><p><strong>建立数据文档</strong>：一次性对所有数据进行编目通常是不可行的，所以需要一种切合实际的方法。首先对最重要的数据进行<span style="color: rgb(0, 0, 0);">编目</span>，然后是第二重要的数据，以此类推。</p></li><li><p><strong>定期更新数据目录</strong>：数据集是不断变化的，所以识别这些变化并更新数据目录至关重要。理想情况下，这个过程应该是自动化的。</p></li><li><p><strong>优化数据交互</strong>：数据目录是一种工具，使企业团队能够有效地与企业的数据交互。了解这些团队的需求并优化相关的标准和规范，为优化数据交互铺平道路。如标准化所有内部数据库、schema、字段、数据沿袭的文档格式。</p></li></ol><section style="margin-top: 0.5em;"><br style="white-space: normal;"/></section><section style="margin-top: 0.5em;"><strong>2）数据清单（Data Inventory）</strong></section><p style="margin-top: 0.5em;"><strong><strong style="white-space: normal;">数据清单</strong>是数据</strong><span style="color: rgb(61, 167, 66);"><strong>清点</strong></span><strong>/盘点的成果。数据清单是集中化的元数据集合</strong>，它<span style="color: rgb(0, 0, 0);">指示了</span>组织收集和维护的所有数据集。该文档（或文档集合）精确定位每个数据集的<span style="color: rgb(61, 167, 66);"><strong>位置</strong></span>及其包含的<span style="color: rgb(61, 167, 66);"><strong>数据类型</strong></span>。</p><p style="margin-top: 0.5em;"><strong>数据分析师</strong>使用数据清单来确定哪些数据可用以及如何访问它们。</p><p style="margin-top: 0.5em;"><strong>数据管理员</strong>维护数据清单，并为每个数据集制定相关的<strong>数据访问策略</strong>。</p><section style="margin-top: 0.5em;"><strong>数据清单的主要挑战是</strong><span style="color: rgb(61, 167, 66);"><strong>保持最新</strong></span>。最有效的方法是通过自动化方式持续更新数据清单。</section><section style="margin-top: 0.5em;"><strong>数据清单的示例</strong>如下：</section><section style="text-align: center;margin-bottom: 0em;margin-top: 0.5em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6662889518413597" data-s="300,640" style="" data-type="png" data-w="1765" src="https://wechat2rss.xlab.app/img-proxy/?k=9c89c7e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNYjxElkicRc050apbP9RNkVZGTJtypicjmaPrcicnr2RNqRGnuHWPUibrowDZ5W9cw2U0d4lSlk17Q7w%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 0.5em;"><br/></section><section style="margin-top: 0.5em;"><strong>3）数据字典（Data Dictionary）</strong><br/></section><section style="margin-top: 0.5em;">数据字典描述了如何<strong>命名和定义数据资产</strong>的信息。数据字典通常包含围绕<strong style="white-space: normal;">数据资产、关系、有关来源和使用的<strong>元数据</strong>、数据schema</strong>等<span style="color: rgb(61, 167, 66);"><strong>术语的集中定义</strong></span>。比如数据资产的<strong>名称</strong>、<strong>设置</strong>和其他<strong>重要属</strong><strong>性</strong>。</section><section style="margin-top: 0.5em;"><strong>数据字典示例。</strong>数据字典通常包含以下元素：</section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p>数据资产名称</p></li><li><p>格式类型</p></li><li><p>与其他数据实体和资产的关系</p></li><li><p>参考数据</p></li><li><p>数据质量规则</p></li><li><p>元素数据资产层级</p></li><li><p>数据存储位置</p></li><li><p>质量指标代码<br/></p></li><li><p>业务规则（数据质量验证和schema对象）</p></li><li><p>实体关系图</p></li></ul><section style="margin-top: 0.5em;">有两种类型的数据字典：<br/></section><ol class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><p><span style="color: rgb(0, 0, 0);"><strong>静态</strong></span><strong>数据字典</strong>：不绑定到任何特定的数据库，因此必须<strong>手动更新</strong>。但手动过程更新的延迟，会导致数据字典中的元数据不同步。</p></li><li><p><span style="color: rgb(0, 0, 0);"><strong>动态</strong></span><strong>数据字典</strong>：会随着它们所链接的数据存储库的增长而<strong>自动更新</strong>。建议组织实施动态数据字典，以确保所有数据字典保持更新和准确。</p></li></ol><section style="margin-top: 0.5em;white-space: normal;"><strong><strong>数据字典</strong>的创建方法。</strong>大多数情况下，<strong>由计算机辅助软件工程创建的</strong><span style="color: rgb(61, 167, 66);"><strong>数据库管理系统和信息系统，都包含动态</strong><strong>数据字典</strong></span>。团队可以使用这些字典作为创建数据字典的起点。<span style="color: rgb(0, 0, 0);">如果您无法自动生成可机读的数据字典，则可以使用单源字典，例如电子表格中包含的字典。</span></section><section style="margin-top: 0.5em;"><br/></section><section style="margin-top: 0.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">为何需要这些数据秘籍</span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p><br/></p><section style="margin-top: 0.5em;white-space: normal;"><strong>1）<strong><span style="text-indent: 34px;"><strong>为何</strong></span>需要</strong>数据目录？</strong></section><p style="margin-top: 0.5em;white-space: normal;"><strong>当您拥有跨多个数据字典且可供多个用户访问的数据时</strong>，最好有一个数据目录。数据目录将这些数据组织成简单、易于消化的形式，从而简化数据提取和处理。</p><p style="margin-top: 0.5em;white-space: normal;"><strong>数据目录有助于改进数据管理</strong>。它们提供组织中可用数据集的<strong>高层级</strong><span style="color: rgb(0, 0, 0);"><strong>类别</strong></span><strong>信息</strong>，从而提供<strong>高层级洞察和分析</strong>。该资产<strong>使干系人能够有效地找到存储在不同位置的任何类型的相关数据集</strong>，例如数据湖、仓库和其他数据库。<br/></p><section style="margin-top: 0.5em;white-space: normal;"><strong>数据目录可支持数据工程操作</strong>。数据目录通过<strong>跟踪数据<span style="color: rgb(0, 0, 0);">schema变更</span></strong><span style="color: rgb(0, 0, 0);">，</span>来支持数据工程操作，以促进数据管道中的转换和聚合。数据目录通过在发生变更时触发警报，来帮助数据工程师检查传入数据是否符合预期<span style="color: rgb(0, 0, 0);">schema</span>。</section><section style="margin-top: 0.5em;white-space: normal;"><strong>数据目录使组织能够有效跟踪数据资产</strong>，并使<span style="caret-color: rgba(0, 0, 0, 0);">干系人</span>能够快速轻松地找到相关数据集，同时适应不断变化的数据环境。</section><section style="margin-top: 0.5em;white-space: normal;"><br/></section><section style="margin-top: 0.5em;"><strong>2）<strong><span style="text-indent: 34px;"><strong>为何</strong></span>需要</strong>数据清单？</strong><br/></section><section style="margin-top: 0.5em;"><strong>数据清单满足</strong><span style="color: rgb(61, 167, 66);"><strong>数据</strong></span><span style="color: rgb(61, 167, 66);"><strong>法规合规性</strong></span>。依据<strong>GDPR（欧洲通用数据保护条例）等数据治理法规</strong>，要求企业知道他们收集和存储的所有敏感数据的位置，这隐含要求了详细和最新的数据清单。这在收集个人身份信息(PII)时尤其重要。</section><section style="margin-top: 0.5em;"><strong><strong style="white-space: normal;">数据清单</strong>提供了数据可见性</strong>。当组织拥有广泛的数据采集时，了解其所拥有的数据及其有用的原因是一项艰巨的任务。而数据清单可以成倍地简化此任务，因为它提供了组织拥有的数据及其位置的详细信息。数据清单为数据消费者提供了数据发现和访问的起点。数据清单也简化了数据跟踪，因为组织的<strong>数据现在本质上是可搜索的</strong>。 </section><section style="margin-top: 0.5em;"><br/></section><p><strong>3）<span style="text-indent: 34px;">为何</span>需要数据字典？</strong></p><p style="margin-top: 0.5em;"><strong style="white-space: normal;">数据字典可以防止数据冗余和歧义</strong>。当企业拥有被许多用户访问的大量的<span style="color: rgb(0, 0, 0);">定量</span>数据时，数据字典是必不可少的，因为它可以<strong>防止数据冗余和歧义</strong>。如果使用得当，数据字典可以提高效率。虽然准备这份文件可能需要一些时间，但长期的结果是值得的。 </p><section style="margin-top: 0.5em;white-space: normal;"><strong>数据字典有助于防止在项目中使用数据资产时出现不一致和冲突</strong>。<br/></section><section style="margin-top: 0.5em;white-space: normal;"><strong>数据字典中的元数据，主要关注数据资产的</strong><span style="color: rgb(61, 167, 66);"><strong>业务属性</strong></span>。它通常促进业务<span style="caret-color: rgba(0, 0, 0, 0);">干系人</span>和技术用户之间的沟通，确保所有信息、内容、格式都满足要求。</section><section style="margin-top: 0.5em;white-space: normal;"><strong>数据字典可用于支持<strong style="white-space: normal;">数据工程</strong>操作</strong>。数据字典<strong style="white-space: normal;">与数据仓库、关系数据库、数据管理系统密切相关</strong>。 </section><section style="margin-top: 0.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">数据秘籍之间的区别</span></span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p><br/></p><section style="margin-top: 0.5em;white-space: normal;"><strong>1）<strong style="white-space: normal;">数据目录</strong><strong> </strong>vs. <strong style="white-space: normal;">数据清单</strong></strong></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 0.5em;"><strong>数据目录</strong>：提供了组织中所有可用数据的<span style="color: rgb(61, 167, 66);"><strong>鸟瞰图</strong></span>以及在<strong>哪里</strong>可以找到这些数据。数据目录通过<strong>根据常规</strong><span style="color: rgb(61, 167, 66);"><strong>业务</strong></span><strong>功能进行组织</strong>，例如了解潜在客户生成管道、管理采购和库存、跟踪客户消费习惯。虽然<strong>数据清单</strong>中的每个条目都是唯一的，但<strong>数据目录可以引用不同条目中的相同数据点</strong>。<br/></section></li><li><section style="margin-top: 0.5em;"><strong>数据清单</strong>：包含组织<strong>所有数据集</strong>的元数据（如每个<strong>数据点</strong>的<strong>位置</strong>和<strong>类型</strong>），使这些数据集本质上是<span style="color: rgb(61, 167, 66);"><strong>可搜索</strong></span>的。它本质上是<strong><span style="color: rgb(61, 167, 66);">细粒度</span></strong>的，提供有关单个数据集的详细信息。<strong>数据清单中的每个条目都是</strong><span style="color: rgb(61, 167, 66);"><strong>唯一</strong></span><strong>的</strong>。数据清单中包含的信息始终是唯一的，而一个数据集可能会出现在<strong>数据目录</strong>的多个条目中。因此，<span style="color: rgb(61, 167, 66);"><strong>数据清单比数据目录更加细化和技术化</strong></span>。</section></li></ul><section style="margin-top: 0.5em;white-space: normal;"><br/></section><section style="margin-top: 0.5em;white-space: normal;"><strong>2）数据目录 vs. 数据字典</strong><br/></section><ul class="list-paddingleft-1" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 0.5em;"><strong>数据目录</strong>：反映了组织中数据资产的整体概况。</section></li><li><section style="margin-top: 0.5em;"><strong>数据字典</strong>：<span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">用于</span><strong style="outline: 0px;max-width: 100%;color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">命名和定义数据资产</strong><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">，目的是<strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">防止数据冗余和歧义</strong><span style="letter-spacing: 0.544px;">。</span></span></section></li></ul><section style="margin-top: 0.5em;"><br/></section><section style="margin-top: 0.5em;"><strong>3）数据清单 vs. 数据字典</strong><br/></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="margin-top: 0.5em;"><strong>数据清单</strong>：详细说明了组织中可用的所有<strong>数据集</strong>，并显示所有相关<strong>元数据</strong>。</section></li><li><section style="margin-top: 0.5em;"><strong>数据字典</strong>：定义了这些数据集的<span style="color: rgb(61, 167, 66);"><strong>规则</strong></span>，指示了它们的正确格式、形状、schema。</section></li></ul><section style="margin-top: 0.5em;white-space: normal;"> <br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><span style="color: rgb(34, 34, 34);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">创建数据秘籍的关键因素</span></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;"> </p><section style="margin-top: 0.5em;">创建数据目录、数据清单、数据字典是现代数据处理中的基本功能。然而，这些过程存在一些固有的常见缺陷，特别是在处理敏感数据和非结构化或半结构化数据时。此时，数据目录、数据清单、数据字典协同工作，共同构成了理解和保护这些数据的基础。</section><section style="margin-top: 0.5em;"><strong>1）重点关注敏感数据</strong></section><section style="margin-top: 0.5em;"><strong>敏感</strong><strong>数据应该被准确地</strong><span style="color: rgb(61, 167, 66);"><strong>标记</strong></span><strong>、编目和清点</strong>，因为知道数据在哪里以及它有多敏感，可以采取进一步的数据保护措施。 </section><section style="margin-top: 0.5em;"><strong>组织应该分配对这些敏感数据的</strong><span style="color: rgb(61, 167, 66);"><strong>所有权</strong></span>，因为知道谁对数据负责会产生保护它的紧迫性。 </section><section style="margin-top: 0.5em;"><strong>限制对敏感数据的</strong><span style="color: rgb(61, 167, 66);"><strong>访问</strong></span>，并在<strong>数据目录</strong>中相应地更新使用和访问指南。  </section><section style="margin-top: 1.5em;"><strong>2）持续敏感数据发现</strong></section><section style="margin-top: 0.5em;">勾勒并实施协议，以不断发现组织数据结构中的敏感数据。如果企业不知道那里有敏感数据，就无法开始保护它。 </section><section style="margin-top: 1.5em;"><strong>3）确保对半结构化数据进行</strong><span style="color: rgb(0, 0, 0);"><strong>分类分级</strong></span><strong>和更新</strong></section><section style="margin-top: 0.5em;"><strong>半结构化数据不适合明确定义的结构或schema</strong><strong>。相反，它是通过</strong><span style="color: rgb(61, 167, 66);"><strong>标签</strong></span><strong>进行组织的</strong>，这些标签允许对它们进行分组和组织。这些<strong>非关系或NoSQL数据类型通常难以捕获、</strong><span style="color: rgb(0, 0, 0);"><strong>分类分级</strong></span><strong>、更新</strong>，但它们构成了数据治理的重要组成部分。 </section><section style="margin-top: 0.5em;">需要实施一些流程来识别和编目<span style="color: rgb(0, 0, 0);">此种</span>数据，以确保组织不会创建一个充满暗数据的湖泊。</section><section style="margin-top: 0.5em;"> </section><section style="margin-top: 0.5em;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;"></span></section>



<p><a href="2247494693">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=48c365ba&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494693%26idx%3D1%26sn%3Dd871fdeffad85c6c0e1bc5f8faf5ae41%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 May 2022 06:09:00 +0800</pubDate>
    </item>
    <item>
      <title>数据治理的三位数据大师</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494690&amp;idx=1&amp;sn=9452cc814060b83d7dfcfb141f6ff176</link>
      <description>想起星战中的尤达大师</description>
      <content:encoded><![CDATA[<p>
原创 <span>启承</span> <span>2022-04-24 06:08</span> <span style="display: inline-block;"></span>
</p>

<p>想起星战中的尤达大师</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=339cc4ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPOn3jicpy5IUlOtwuMQCj3pFib4omMhfYjsY0zPGX5Rkib1p4kicogQTVgEWry2M0dbicATkvplSIRNsAw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<span style="color: rgb(0, 0, 0);"><strong>30</strong><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>5</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 0.5em;">数据的价值取决于数据治理的效果。而<strong><span style="text-align: left;">数据治理工作</span>有一个至关重要的基</strong><strong>础——</strong><strong>具有明确的</strong><span style="color: rgb(61, 167, 66);"><strong>数据治理角色</strong></span><strong>，并确保所有干系人理解这些角色之间的差异。</strong></p><p style="text-align: left;margin-top: 0.5em;"><strong>完备的数据治理角色应该包含</strong><span style="color: rgb(61, 167, 66);"><strong>三位数据大师</strong></span><strong>：</strong>1）<strong>数据所有者</strong>：对数据治理的<span style="color: rgb(61, 167, 66);"><strong>结果</strong></span>负责；2）<strong>数据管理员</strong>：对数据治理的<span style="color: rgb(61, 167, 66);"><strong>任</strong></span><span style="color: rgb(61, 167, 66);"><strong>务</strong></span>负责；3）<strong><span style="text-align: left;">数据保管员</span></strong><span style="text-align: left;">：对数据</span><span style="text-align: left;color: rgb(61, 167, 66);"><strong>安</strong><strong>全</strong></span><span style="text-align: left;">负责</span>。</p><p style="text-align: left;margin-top: 0.5em;">这些角色叫什么名字，并不重要。最重要的是：为什么这些角色如此重要？组织为什么应该关心这个问题？<br/></p><p style="text-align: left;margin-top: 0.5em;"><strong>数据治理</strong>对网络安全至关重要，因为网络安全的核心是保护<strong>数据</strong>免受网络威胁。当把<strong>数据治理</strong>与<strong>网络安全</strong>结合时，就产生了<strong>数据安全治理</strong>的需求。而<strong>作为数据安全治理的工具</strong>，一个好的<span style="color: rgb(61, 167, 66);"><strong>数据安全平台</strong></span><span style="color: rgb(0, 0, 0);">，应</span>使<strong>三位</strong><strong style="text-align: left;white-space: normal;">数据大师</strong>能够各司其职，共同执行组织的数据安全治理工作。</p></section></section></section></section></section><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section>1.企业的数据是资产还是负债？<br/></section><p style="margin-top: 0.5em;white-space: normal;">2.三位“数据大师”</p><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">1）数据所有者（数据主人）</section><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">2）数据管理员<span style="text-indent: 34px;">（数据管家</span><span style="text-indent: 34px;">）</span></section><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">3）数据保管员（数据卫士）</section><p style="margin-top: 0.5em;white-space: normal;">3.数据治理角色之间的差异</p><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">1）数据所有者 vs. 数据管理员</section><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">2）数据所有者 vs. <span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span></section><section style="margin-top: 0.5em;white-space: normal;text-indent: 2em;">3）数据管理员 vs. 数据保管员<span style="text-indent: 2em;"></span></section><p style="margin-top: 0.5em;white-space: normal;">4.数据治理角色的示例</p><section style="white-space: normal;margin-top: 2em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="white-space: normal;">企业的数据是</strong></strong></span></strong></span></strong></strong></strong></strong></span><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;color: rgb(61, 167, 66);"><strong><strong><strong><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;text-align: center;"><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;text-indent: 34px;"><strong style="text-align: left;"><strong>资产</strong></strong></span></strong></span></strong></strong></strong></strong></span><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="white-space: normal;">还是</strong></strong></span></strong></span></strong></strong></strong></strong></span><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;color: rgb(61, 167, 66);"><strong><strong><strong><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;text-align: center;"><strong><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;text-indent: 34px;"><strong style="text-align: left;"><strong>负债</strong></strong></span></strong></span></strong></strong></strong></strong></span><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="white-space: normal;">？</strong></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 0.5em;">大多数企业的业务主管都认同，数据已经成为组织的宝贵资源。而且数据的规模在快速扩大。<br/></p><p style="margin-top: 0.5em;white-space: normal;">但是，数据在企业中可能扮演截然不同的角色。特别是对于现代监管环境中的组织而言，<strong>糟糕的数据治理可能会将数据转化为严重的</strong><span style="color: rgb(61, 167, 66);"><strong>负债</strong></span><strong>，而不是资产</strong>，从而使企业面临严重的隐私处罚。</p><p style="margin-top: 0.5em;white-space: normal;"><strong style="white-space: normal;">只有当我们知道如何使用数据、正确管理数据并给予它应有的尊重时，数据才会有价值，才能变成</strong><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">资产</strong></span><strong style="white-space: normal;">。</strong></p><p style="margin-top: 0.5em;white-space: normal;">当今的普遍现象是，组织在缺乏良好数据治理的情况下开展业务运营：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;white-space: normal;">组织通常拥有大量数据，但<strong>没有很好地记录或标准化</strong>，因此他们<strong>不了解所拥有的数据</strong>。</p></li><li><p style="margin-top: 0.5em;white-space: normal;">即使他们了解，他们在<strong>查找或访问恰当的数据</strong>时，也会遇到障碍。</p></li><li><p style="margin-top: 0.5em;white-space: normal;">即使组织可以找到他们想要的数据，他们通常也不能完全确定它<strong>是否足够可靠</strong>。</p></li></ul><p style="margin-top: 0.5em;">一个数据驱动型组织，应该制定数据管理的完善制度。同样重要的是，拥有一个数据治理团队，充分了解数据治理过程中的具体角色和职责。<br/></p><p style="margin-top: 0.5em;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据治理中的三位数据大师</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 0.5em;">如果您研究过数据治理的实施，您肯定已经遇到过许多角色。以下是任何组织在数据治理背景下都需要了解的三个最重要的角色：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>数据所有者</strong>（<strong>数据主人</strong>）</p></li><li><p style="margin-top: 0.5em;"><strong>数据管理员</strong>（<strong>数据管家</strong>）</p></li><li><p style="margin-top: 0.5em;"><strong><span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span></strong>（<strong>数据卫士</strong>）</p></li></ul><p style="margin-top: 0.5em;">注意，在现实中，上述数据治理角色中的任何一个，都很少对应于组织中的一个专门岗位。也就是说，<span style="color: rgb(61, 167, 66);"><strong>上述角色与现实岗位并非一一对应</strong></span>。因为在多数情况下，企业并不会<span style="color: rgb(0, 0, 0);">雇用一个人承担一个新岗位</span>。而是利用现有的团队成员，来同时承担各种数据治理职责。</p><p style="margin-top: 2em;"><strong>1）什么是数据所有者？</strong><br/></p><p style="margin-top: 0.5em;"><strong>数据所有者：应对组织内一个或多个数据集的分级分类、保护、使用、质量，担负责任</strong>。此责任涉及的活动包括但不限于确保：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;">组织的<strong>数据词汇表</strong>是全面的，并得到所有干系人的同意；</p></li><li><p style="margin-top: 0.5em;">建立了审计和报告<strong>数据质量</strong>的系统；</p></li><li><p style="margin-top: 0.5em;"><strong>数据质量问题</strong>的上报矩阵已就位；</p></li><li><p style="margin-top: 0.5em;">采取措施在规定的时间范围内解决<strong>数据质量问题</strong>。</p></li></ul><p style="margin-top: 0.5em;">大多数数据治理专家都认为，<strong>给定的数据集应该</strong><span style="color: rgb(61, 167, 66);"><strong>只有一个数据所有</strong><strong>者</strong></span>。如果多个干系人都关注同一组数据，则应该指定其中一个人来担任数据所有者角色。</p><p style="margin-top: 0.5em;">为履行上述职责，数据所有者需要：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;">有权在工作流、实践、基础设施方面进行任何必要的变更，以确保数据质量；</p></li><li><p style="margin-top: 0.5em;">启动确保数据质量的措施的资源，例如数据清洗和数据审计。</p></li></ul><p style="margin-top: 0.5em;">实际上，这意味着<strong>必须将数据所有者角色分配给相对高级的人员，通常是企业</strong><span style="color: rgb(61, 167, 66);"><strong>高层管理人员</strong></span>。如果没有足够的权限和对资源的访问权限，数据所有者将无法有效地履行其职责，而这一缺陷会沿着整个数据治理链向下传递，从而使整个数据治理工作失败。</p><p style="margin-top: 0.5em;">然而，<strong>大多数高级管理人员不一定了解有关数据集及其管理的更精细的技术细节</strong>。他们也几乎总是受到时间限制，这意味着<strong>他们无法实际实施</strong>数据治理所需的所有流程。<strong>这就需要数据管理员派上用场</strong>。</p><p style="margin-top: 2em;"><strong>2）什么是数据管理员？</strong></p><p style="margin-top: 0.5em;"><strong>数据管理员：是对特定数据集有透彻了解的</strong><span style="color: rgb(61, 167, 66);"><strong>主题专家</strong></span>，负责确保数据的分级分类、保护、使用、质量，符合<strong>数据所有者</strong>设定的数据治理标准。一些组织也将此角色称为“<strong style="white-space: normal;">数据</strong><span style="color: rgb(61, 167, 66);"><strong style="white-space: normal;">质</strong><strong style="white-space: normal;">量</strong></span><strong style="white-space: normal;">管理员</strong>”。</p><p style="margin-top: 0.5em;">注意，<strong>主题专家</strong><strong>不一定具有IT背景</strong>。根据组织的数据和业务性质，主题专家可能具有<strong>业务、运营、IT、项目</strong>职能方面的经验。</p><p style="margin-top: 0.5em;">典型情况下，<span style="color: rgb(0, 0, 0);"><strong>数据所有者会任命</strong></span><span style="color: rgb(61, 167, 66);"><strong>一名</strong></span><span style="color: rgb(0, 0, 0);"><strong>数据管理员</strong></span><strong>。</strong>当然，也可以根据组织及其数据的规模，任命<span style="color: rgb(61, 167, 66);"><strong>多名</strong></span>数据管理员，来协助数据所有者执行组织的数据治理策略。</p><p style="margin-top: 0.5em;"><strong style="white-space: normal;">尽管<strong style="white-space: normal;">数据管理员</strong>不拥有数据，但他们必须彻底理解<strong style="white-space: normal;">这些数据</strong>被如何记录、存储、保护</strong>。</p><p style="margin-top: 0.5em;"><strong style="white-space: normal;">数据管理员</strong>还可以细分为<strong>四种不同类型</strong>：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>业务(Business)</strong>数据管理员</p></li><li><p style="margin-top: 0.5em;"><strong>运营(Operational)</strong>数据管理员</p></li><li><p style="margin-top: 0.5em;"><strong>技术(Technical)</strong>数据管理员</p></li><li><p style="margin-top: 0.5em;"><strong>项目(Project)</strong>数据管理员</p></li></ul><p style="margin-top: 0.5em;">列出的每一个角色，都反映了该角色在组织中的职能背景。当组织需要不同类型的数据管理员或多个相同类型的数据管理员来处理共同的数据集时，他们需要协同工作以确保有效的数据治理。</p><p style="margin-top: 0.5em;">在许多情况下，<strong>数据管理员可能不一定具备管理数据存储、检索、格式化的专业知识</strong>。这又需要下一个角色：数据保管员<span style="text-indent: 34px;"></span>。</p><p style="margin-top: 0.5em;"> </p><p style="margin-top: 0.5em;"><strong>3）什么是<span style="text-indent: 34px;">数据保管员</span>？</strong></p><p style="margin-top: 0.5em;"><strong><strong style="white-space: normal;"><span style="text-indent: 34px;">数据保管员</span></strong>：负责实施和维护给定数据集的</strong><span style="color: rgb(61, 167, 66);"><strong>安全控制</strong></span>（包括对数据进行维护、归档、恢复、备份，防止数据泄露/损坏等）以满足<strong>数据所有者</strong>在数据治理框架中指定的要求。</p><p style="margin-top: 0.5em;">数据保管员通常是<span style="color: rgb(61, 167, 66);"><strong>IT</strong><strong>部门</strong></span><span style="color: rgb(61, 167, 66);"><strong>的成员</strong></span>。通常在其专业领域进一步划分，例如：<strong>数据建模师、数据架构师、数据库管理员</strong>等。</p><section style="margin-top: 2em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据治理角色之间的差异</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 0.5em;">与数据治理相关的不同角色的名称，存在很多混淆。</p><p style="margin-top: 2em;"><strong>1）数据所有者<span style="text-indent: 34px;"> </span><span style="text-indent: 34px;">vs. </span>数据管理员</strong><br/></p><p style="margin-top: 0.5em;"><strong>数据所有者和数据管理员之间有什么区别？</strong><br/></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>数据所有者对</strong><span style="color: rgb(61, 167, 66);"><strong>数据治理结果</strong></span><strong>负责，</strong><span style="color: rgb(61, 167, 66);"><strong><strong>以结果为导向</strong></strong></span><strong>；</strong></p></li><li><p style="margin-top: 0.5em;"><strong>数据管理员对具体的</strong><span style="color: rgb(61, 167, 66);"><strong>数据治理任务</strong></span><strong><span style="color: rgb(0, 0, 0);">负</span></strong><strong><span style="color: rgb(0, 0, 0);">责</span></strong><span style="color: rgb(0, 0, 0);"><strong style="">，</strong></span><span style="color: rgb(61, 167, 66);"><strong>以任务为导向</strong></span>。</p></li></ul><p style="margin-top: 0.5em;">例如，数据所有者可能对<strong>数据<span style="color: rgb(0, 0, 0);">卓越</span>指标</strong>负责，例如审计结果和质量分数。他们还可能对<strong>业务指标</strong>负责，例如数据治理对战略目标的影响。</p><p style="margin-top: 0.5em;">相比之下，数据管理员可能负责确保数据治理清单上的所有项目都得到<strong>实施</strong>，并及时预防和解决实施中的问题。</p><p style="margin-top: 0.5em;"><strong>企业组织是否同时需要数据所有者和数据管理员？</strong>这取决于企业的数据治理计划的规模和范围。<strong>大型组织很可能同时需要这两种角色；而在小型企业中，数据所有者和数据管理员可以是同一个人。</strong></p><p style="margin-top: 2em;"><strong>2）数据所有者<span style="text-indent: 34px;"> </span><span style="text-indent: 34px;">vs. </span><span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span></strong></p><p style="margin-top: 0.5em;"><span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span>通常是物理地或直接地处理数据集的存储和安全性的人员。但仅仅因为数据存储在某人控制的设备上，并不能使他们成为数据所有者。 就像银行客户将钱存入银行时，仅仅因为钱存放在银行中，并不能使银行成为这笔钱的所有者。</p><p style="margin-top: 0.5em;"><strong>数据所有者和<span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span>之间有什么区别？</strong></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>数据所有者</strong><strong>通常<strong style="white-space: normal;">是</strong>担任高级</strong><span style="color: rgb(61, 167, 66);"><strong>业务</strong><strong>角</strong><strong>色</strong></span><strong>的人员</strong>，负责一组或多组数据的分级分类、保护、使用、质量。</p></li><li><p style="margin-top: 0.5em;"><strong><span style="text-indent: 34px;">数据保管员</span>通常是担任</strong><span style="color: rgb(61, 167, 66);"><strong>IT角色</strong></span><strong>的人员</strong>，负责以符合组织数据治理策略的方式，维护一个或多个数据集的<strong>存储和安全基础设施</strong>。</p></li></ul><p style="margin-top: 0.5em;"><strong>在小型组织中，数据所有者和数据保管员的角色可能由同一个人担任</strong>。</p><section style="margin-top: 2em;"><span style="text-indent: 34px;"></span><strong><span style="text-indent: 34px;">3</span><span style="text-indent: 34px;">）数据</span><span style="text-indent: 34px;">管理员</span><span style="text-indent: 34px;"> </span><span style="text-indent: 34px;">vs. 数据<strong style="white-space: normal;"><span style="text-indent: 34px;">保管员</span></strong></span></strong></section><p style="margin-top: 0.5em;"><span style="text-indent: 34px;">数据管理员和数据保管员在数据治理中起着相互补充的作用。两者都被分配了一组他们负责的数据资产。</span></p><p style="margin-top: 0.5em;"><span style="text-indent: 34px;"><strong style="white-space: normal;"><span style="text-indent: 34px;">数据管理员和数据保管员的主要区别在于：</span></strong><span style="text-indent: 34px;">数据保管员从</span></span><span style="color: rgb(61, 167, 66);"><strong><span style="text-indent: 34px;">技术</span></strong></span><span style="text-indent: 34px;">角度对数据资产负责。数据管理员从</span><span style="color: rgb(61, 167, 66);"><strong><span style="text-indent: 34px;">业务</span></strong></span><span style="text-indent: 34px;"><span style="text-indent: 34px;">角度对数据资产负责。</span><strong style="white-space: normal;"></strong></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong><span style="text-indent: 34px;">数据管理员</span></strong><span style="text-indent: 34px;">：负责与一组数据资产相关的</span><span style="text-indent: 34px;color: rgb(61, 167, 66);"><strong>业务</strong></span><span style="text-indent: 34px;"><strong>控制</strong>、数据内容和元数据管理。他们与受数据影响的干系人合作，制定定义、标准、数据控制。他们还可以支持数据质量、数据采集、数据输入计划。在许多情况下，使用相同数据的业务部门和运营部门对数据的看法并不相同。数据管理员是确保数据支持所有业务需求和法规要求的人。</span></p></li><li><p style="margin-top: 0.5em;"><strong><span style="text-indent: 34px;">数据保管员</span></strong><span style="text-indent: 34px;">：负责数据的</span><span style="text-indent: 34px;color: rgb(61, 167, 66);"><strong>技术</strong></span><span style="text-indent: 34px;"><strong>控制</strong>，包括安全性、可扩展性、配置管理、可用性、准确性、一致性、审计跟踪、备份和恢复、技术标准、策略和业务规则实施。</span></p></li></ul><p style="margin-top: 0.5em;">注意：在实际工作中，分配给这两种角色的，<strong>通常是个人，而非团队</strong>。</p><p style="margin-top: 0.5em;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据治理角色的真实示例</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 0.5em;">要了解数据管理在实践中如何发挥作用，让我们看一下这些角色在不同组织中的几个示例。</p><p style="margin-top: 2em;"><strong>1）零售链中的数据管理</strong></p><p style="margin-top: 0.5em;">一家高端零售连锁店让顾客参与抽奖活动，需要顾客将名片放入位于每家店面的<span style="color: rgb(0, 0, 0);">抽奖箱</span>。通过提供顾客的个人数据并参加抽奖，顾客同意接收连锁店的营销电子邮件。</p><p style="margin-top: 0.5em;">在这种情况下，<span style="color: rgb(61, 167, 66);"><strong>自下而上</strong></span>开展数据管理：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>数据创建者</strong>：一名<strong>后台员工</strong>收集并手动记录每个客户的数据，录入公司数据库。此人不是数据所有者、数据管理员、数据保管员，而只是<span style="color: rgb(61, 167, 66);"><strong>数据创建者</strong></span>。</p></li><li><p style="margin-top: 0.5em;"><strong>数据保管员</strong>：客户数据存储在云服务器上，<strong>IT管理员</strong>是<strong><span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span></strong>，必须确保数据安全且只有授权人员才能访问。</p></li><li><p style="margin-top: 0.5em;"><strong>数据管理员：营销人员</strong>负责在电子邮件营销活动使用数据集之前清理和验证数据集。他被任命为<strong>数据管理员</strong>，负责通过数据治理<span style="color: rgb(0, 0, 0);">策略</span>规定的格式化、清洗、富化程序，来确保电子邮件营销数据的质量。</p></li><li><p style="margin-top: 0.5em;"><strong><strong style="white-space: normal;">数据所有者</strong>。销售主管</strong>对销售目标负责，并且非常重视营销活动的成功。他被指定为该数据集的<strong>数据所有者</strong>，因为他处于高级职位，可以洞察组织的目标，并且拥有权力和资源来做出提高数据质量和安全性的决策（例如，通过执行身份验证保护措施以允许访问数据）。</p></li></ul><p style="margin-top: 2em;"><strong>2）制造企业中的数据管理</strong></p><p style="margin-top: 0.5em;white-space: normal;">在这种情况下，<span style="color: rgb(61, 167, 66);"><strong>自<strong style="white-space: normal;">上</strong>而<strong style="white-space: normal;">下</strong></strong></span>开展数据管理：</p><p style="margin-top: 0.5em;"><strong style="white-space: normal;">数据所有者</strong>：在制造企业中，<strong>生产经理</strong>被指定为所有生产数据的<strong>数据所有者</strong>。<br/></p><p style="margin-top: 0.5em;"><strong style="white-space: normal;">数据管理员</strong>：数据所有者任命了<strong>几个</strong><strong>数据管理员</strong>：</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-top: 0.5em;"><strong>生产</strong>数据管理员：<strong>生产轮班主管</strong>是材料使用、循环时间、零件输出数据的数据管理员；</p></li><li><p style="margin-top: 0.5em;"><strong>维护</strong>数据管理员：<strong>维护工程</strong><strong>师</strong>是机器性能、可用性、故障、维修时间等数据的数据管理员；</p></li><li><p style="margin-top: 0.5em;"><strong>计划</strong>数据管理员：<strong>生产计划员</strong>是利用率和效率数据的数据管理员；</p></li><li><p style="margin-top: 0.5em;"><strong>质</strong><strong>量</strong>数据管理员：<strong>质量主管</strong>是缺陷和拒收数据的数据管理员。</p></li></ul><p style="margin-top: 0.5em;"><strong><strong><span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span></strong></strong>：这些数据被捕获并存储在本地服务器中，该服务器由组织的IT部门操作和管理，<strong>IT部</strong>门的一名员工被任命为<span style="text-indent: 34px;">数据</span><span style="text-indent: 34px;">保管员</span>。<br/></p><p style="margin-top: 0.5em;"><br/></p><p style="margin-top: 0.5em;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;"></span><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></p>



<p><a href="2247494690">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5d5e28bf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494690%26idx%3D1%26sn%3D9452cc814060b83d7dfcfb141f6ff176%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 24 Apr 2022 06:08:00 +0800</pubDate>
    </item>
    <item>
      <title>安全的未来是上下文</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494638&amp;idx=1&amp;sn=916311c9c461e000bb71ca7e1f6328f9</link>
      <description>Context (上下文) 和 Content (内容)</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2022-03-09 05:30</span> <span style="display: inline-block;"></span>
</p>

<p>Context (上下文) 和 Content (内容)</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b686a4ef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPPuicwVecYaTGwicoZxQ4iccmDPnO8LGZ9esGYrdDXxguRW6VpM2Nw3URhXHgvUafh2oGvy0XIeroW9w%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<span style="color: rgb(0, 0, 0);"><strong>60</strong><strong>00</strong></span>字  <span style="color: rgb(0, 0, 0);"><strong>13</strong></span>图表  阅读约<span style="color:#000000;"><strong>10</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><span style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;">VirusTotal</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">称：“</span><span style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">上下文是王道</strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">”</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">。一位营销大师说</span>：“如果<strong>内容（Content）</strong>为王，那么<strong>上下文（Context）</strong>就是上帝。<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">”</span></span><span style="background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">辩证地看，</span><span style="background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">上下文和<span style="letter-spacing: 0.544px;">内容</span>是既<strong>对立</strong>又<strong>统一</strong>的关系。两者相辅相成，还可以相互转化。</span><span style="background-color: rgb(255, 255, 255);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;"></span></p><p style="margin-top: 10px;white-space: normal;text-align: left;"><strong>上下文是什么</strong>？有人认为是<strong>环境</strong>、<strong>语境</strong>、<strong>背景、情报</strong>，有人认为：低阶的上下文是<strong>属性</strong>（比如黑客组织的攻击特征和作案方式）；高阶的上下文是<strong>意图</strong>（比如黑客组织的攻击原因和战略目的）。非常明确的是，<strong>属性</strong>隶属于上下文的范畴。因此，<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">ABAC（基于</span><strong style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;white-space: normal;">属性</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">的访问控制）</span>是上下文的典型应用。而零信任则将上下文发挥到极致。</p><p style="margin-top: 10px;white-space: normal;text-align: left;">本文最重要的工作是将<strong>零信任访问模型</strong>推演为<strong>零信任操作模型</strong>。零信任的重要特征是<strong>动态性</strong>（时间维度）和<strong>细粒度</strong>（空间维度），而这两种特征都完全依赖于<strong>上下文</strong>。既然零信任访问和上下文的关系如此密切，那么零信任操作与上下文的密切关系也是顺理成章的。如此一来，也就容易理解：不仅<strong>安全访问的未来是上下文</strong>，<strong>安全操作的未来也是上下文</strong>。</p><section style="margin-top: 10px;white-space: normal;text-align: left;">本文还梳理了<strong>上下文的各种类型</strong>（参见表6），如环境上下文、社区上下文、流程上下文、内容上下文、身份上下文、应用程序上下文、操作系统上下文、设备上下文、网络上下文。本文也梳理了<strong>获取各种类型上下文的方法和来源</strong>（参见表7）。这些对于上下文的实操，具有重要价值。</section><section style="margin-top: 10px;white-space: normal;text-align: left;">笔者的另一个断言：<strong>上下文的未来是</strong><span style="color: rgb(172, 57, 255);"><strong>图谱</strong></span><strong>化</strong>。因为<strong>语义</strong>表达是上下文的最高境界，而知识图谱正是<span style="text-align: left;">上下文的语义表达</span>。笔者展示了几个网络安全领域的图谱（<strong>VirusTotal图谱、CrowdStrike威胁图谱、RecordedFuture安全情报图谱、Securiti个人数据图谱</strong>），作为趋势的证词。</section><section style="margin-top: 10px;white-space: normal;text-align: left;">笔者最终断言：<strong style="outline: 0px;max-width: 100%;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;">安全的未来是</strong></span></strong></span></strong></strong></strong></strong><span style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;text-align: left;box-sizing: border-box !important;overflow-wrap: break-word !important;">安全云</strong></span></strong></span></strong></strong></strong></strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">。</span>大数据、图谱、云是阻止当今威胁的三个关键。三者合在一起，就是笔者所说的“<strong>安全云</strong>”。</section></section></section></section></section></section><section style="text-align: center;margin-bottom: 15px;margin-top: 25px;"><strong style="font-size: 20px;text-align: center;">目  录</strong></section><section>1.开门见山：Context（上下文）和 Content（内容）<br/></section><p>2.进入正题：网络安全中的<strong>上下文感知</strong></p><p>3.<strong>模型推演</strong>：从<strong>安全访问模型</strong>到<strong>安全操作模型</strong></p><p>4.<strong>范式转变</strong>：<strong>信任度量</strong>需要实时上下文</p><p>5.五彩纷呈：<strong>安全上下文</strong>的<strong>类型</strong>和<strong>来源</strong><br/></p><p>6.展望未来：上下文的未来是<strong>图谱化</strong></p><p>7.最终陈述<span style="text-align: center;text-indent: 34px;">：安全的未来是<strong>安全云</strong></span></p><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">开门见山：Context（上下文）和 Content（内容）</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;white-space: normal;">Context（上下文）和 Content（内容）是一个有趣的话题。不妨看看几个有趣的对比：</section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.5" style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;white-space: normal;" data-type="png" data-w="2000" src="https://wechat2rss.xlab.app/img-proxy/?k=6f6635e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPuicwVecYaTGwicoZxQ4iccmDtFniacLurXmkI1GcXicgibz4ayXCPF4qsfH1CAsibCXgdWVtGe1fVnS93g%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;text-align: center;">图1-<strong style="white-space: normal;">Conte</strong><span style="color: rgb(172, 57, 255);"><strong>x</strong></span><strong style="white-space: normal;">t（上下文）和 Conte</strong><span style="color: rgb(172, 57, 255);"><strong>n</strong></span><strong style="white-space: normal;">t（内容）</strong><br/></section><section style="margin-top: 15px;"><strong>字形的对比</strong>。上图很有趣：图中的倒影并<strong>不是Conte</strong><span style="color: rgb(172, 57, 255);"><strong>x</strong></span><strong>t（上下文），而是Conte</strong><span style="color: rgb(172, 57, 255);"><strong>n</strong></span><strong>t（内容）</strong>。两者只有一个字母之差，但两者却是几乎对立的含义。<br/></section><section style="margin-top: 15px;"><img class="rich_pages wxw-img" data-ratio="0.779707495429616" style="text-align: center;" data-type="png" data-w="1094" src="https://wechat2rss.xlab.app/img-proxy/?k=17f1b132&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNAeK3veCttQd1Fe6T04IZJFRYZbIlWdQSgmwgrSRTia5Br83w8ZFP8NAc9QJicZ3ibNCgUjWicibOJlDQ%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;text-align: center;">图2-上下文的意义/价值</section><section style="margin-top: 15px;"><strong>上下文的价值</strong>。从上图可以看出，<span style="text-align: center;">上下文（Context）</span>分别赋予了数据（Data）、内容（Content）、信息（Information）以更多的意义和价值。正是<strong>在上下文的作用下</strong>，数据转化成内容，内容转化成信息，信息转化成知识。<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">上下文（Context）和</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">内容（Content）</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">是既</span><strong style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;white-space: normal;">对立</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">又</span><strong style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;white-space: normal;">统一</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">的关系。</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">两者相辅相成，还可以相互转化。</span><br/></section><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5046875" data-s="300,640" style="" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=375118af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNAeK3veCttQd1Fe6T04IZJKfMq5sscUKbkjnfg7cZlHhBJOpLdd9icLNCbkDickLCjmxKfskoOgoNg%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-top: 15px;">图3-内容离不开上下文<br/></section><section style="margin-top: 15px;"><strong>上下文的地位</strong>。微软创始人比尔·盖茨曾说过<strong>内容为王</strong>。营销大师Gary Vaynerchuk却说：“如果内容为王，那么上下文就是上帝。”<br/></section><section style="white-space: normal;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">进入正题：<strong><strong><strong><strong><span style="text-align: center;"><strong><strong style="text-align: left;">网络安全</strong></strong></span></strong></strong></strong></strong>中的上下文感知</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;"><strong>1）上下文感知的含义</strong></section><section style="margin-top: 15px;"><strong>上下文（Context）</strong>是<strong>某事物</strong>存在或发生的<strong>环境/条件/情况/背景</strong>，可以帮助解释或理解该事物。这里的“<strong>某</strong><strong style="white-space: normal;">事物</strong>”也可以理解为上一节中的<strong>内容（Content）</strong>。</section><section style="margin-top: 15px;"><strong>上下文感知安全</strong>，是在做出决策时使用<strong>补充性上下文信息</strong>，来改进安全决策。为了更快、更准确地评估某个给定的<strong style="white-space: normal;">操作</strong>请求应该被允许还是拒绝，需要在做出安全决策时加入更多<strong style="white-space: normal;">实时上下文</strong>信息。</section><p style="margin-top: 25px;"><strong>2）上下文感知的示例</strong><br/></p><section style="margin-top: 15px;">当今，<strong>所有网络安全领域都在向上下文感知基础设施转变</strong>。<strong>应用程序感知、身份感知、内容感知、流程感知、环境感知</strong>，都是向上下文感知转变的例子。</section><section style="margin-top: 15px;"><strong>先看几个熟知的传统型转变：</strong></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><section style="margin-top: 5px;"><strong>网络级防火墙是最先转型的</strong>。下一代防火墙已经超越了传统的静态网络级属性（例如端口号或IP 地址），特别强调<strong>应用程序感知</strong>能力，也开始强调<strong>身份感知</strong>能力。</section></li><li><section style="margin-top: 5px;"><strong>入侵防御系统 (IPS)</strong> ：下一代IPS系统不再将所有IPS规则应用于所有流量，而是使用实时<strong>上下文</strong>知识，包括工作负载正在运行的操作系统或应用程序的哪个版本，以及它们所保护的系统中存在哪些漏洞。这些上下文提高了IPS决策的速度和准确性，节省处理资源，减少误报率。</section></li><li><section style="white-space: normal;margin-top: 5px;"><strong>端点保护平台 (EPP)</strong> ：EPP的发展早已超越了传统的基于签名的白名单和黑名单方法，正在使用<strong>公开情报</strong>和<strong>社区声誉</strong>，来确定给定的可执行代码是否足够可信。<br/></section></li><li><section style="white-space: normal;margin-top: 5px;"><strong>安全Web网关 (SWG)</strong> ：SWG的发展远远超越了传统的静态URL过滤，以在策略决策点处融合<strong>上下文</strong>信息，例如URL的信誉、源IP地址的位置和信誉等。同时也增强<strong>内容感知</strong>，以监控出站连接上的数据泄露。</section></li></ul><section style="margin-top: 15px;white-space: normal;"><strong>再看几个流行的现代型转变：</strong></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="margin-top: 5px;"><strong>网络准入控制 (NAC)</strong>：无论是用于访客网络、VPN访问、全网络访问，NAC解决方案会在允许工作站连接到企业网络之前，使用实时上下文信息，如对设备的<strong>“健康”评估</strong>（即零信任终端环境感知）。<br/></p></li><li><p style="margin-top: 5px;"><strong>身份和访问管理</strong>：身份验证在认证决策点融入了更多<strong>实时上下文</strong>，例如当事务上下文反映异常行为时，则需要更强的身份验证。</p></li><li><p style="margin-top: 5px;"><span style="white-space: pre-wrap;"><strong>授权决策</strong>：授权决策也变得更加上下文化</span>。超越了传统的<strong>RBAC</strong>（基于角色的访问控制）静态模型，积极向<strong>ABAC</strong>（基于属性的访问控制）的零信任架构转变。</p></li><li><p style="margin-top: 5px;"><strong>数据保护</strong>：为了在整个数据生命周期和整个企业IT生态系统中充分保护敏感信息，策略执行点变得更加<strong>内容感知</strong>和<strong>身份感知</strong>，支持根据操作时确定的数据分级分类而动态应用策略。</p></li></ul><section style="margin-top: 15px;">下面，笔者将对这些上下文感知转型示例，进行归纳提升和模型推演，总结出一般性规律。<br/></section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">模型推演：从安全访问模型到安全操作模型</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 15px;"><strong style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;text-align: left;"><span style="font-size: 17px;">1）零信任访问模型</span></strong><br/></p><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;"><span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">零信任访问</span>的目的是：在不可信环境中，实现实体对资源的安全访问。它本质上是要做出一个<strong>安全访问决策</strong>：在当前的<strong>上下文</strong>中，<strong>主体</strong>能否<strong>访问客体</strong>？</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="font-size: 17px;">笔者绘制了如下</span><strong style="font-size: 17px;">零信任访问模型</strong><span style="font-size: 17px;">：</span></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><img class="rich_pages wxw-img" data-ratio="0.776813880126183" data-w="1268" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b297c7db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5LPLBGOMmhoKUyyI93yJdRZH3kX8gllUR0riceo7iaXPNcQjxNr6jArfA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: center;line-height: 1.5em;"><span style="font-size: 17px;">图4-实体之间的安全访问模型</span><br/></section><p style="margin-top: 25px;"><span style="font-size: 17px;"></span><strong style="font-family: PingFangSC-light;font-size: 16px;letter-spacing: 2px;text-align: left;"><span style="font-size: 17px;">2）零信任操作模型</span></strong></p><p>笔者将上述零信任思想推广到<strong>各种</strong><span style="color: rgb(172, 57, 255);"><strong>操作</strong></span><strong>类型</strong>（而不仅仅只是<span style="color: rgb(172, 57, 255);"><strong>访问</strong></span>这种操作），就可以得到下面的零信任安全操作模型：<span style="text-align: center;"></span></p><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.8383280757097792" data-w="1268" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1cc3942c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5L9OGfCXrua5qy6Fjgia7LdUbG5Onju8KicK0micp9g80zIyPeQRJ1XV3w%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图5-实体之间的安全操作模型</section><section style="margin-top: 15px;"><strong style="color: rgb(172, 57, 255);white-space: normal;">分层IT技术栈模型</strong>。在上图中，左右两侧的实体A和实体B，按照<strong>IT技术栈</strong>进行了<strong>分层</strong>，即网络、设备、操作系统 (OS)、应用程序、身份、内容、业务流程。在这种<span style="color: rgb(0, 0, 0);"><strong>分层IT技术栈模型</strong></span>中，各个层级都包含其物理或逻辑实体（对象）——数据包、机器、应用程序、服务、用户、组、事务等。</section><section style="margin-top: 15px;"><span style="color: rgb(172, 57, 255);"><strong>安全操作决策</strong></span><strong>：安全的本质是</strong><span style="color: rgb(0, 0, 0);"><strong>对</strong><strong>操作的安全决策</strong></span>。结合上图来看，网络安全可以被视为一组<strong>安全</strong><strong>决策</strong>的执行，以实现IT堆栈中<strong>不同实体之间的操作</strong>。如上图所示，<strong>当左侧任何层的实体A想要对右侧的实体B进行</strong><span style="color: rgb(172, 57, 255);"><strong>操作</strong></span><strong>时，就会发生</strong><span style="color: rgb(172, 57, 255);"><strong>安全决策</strong></span>。例如：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="margin-top: 5px;"><strong>网络通信</strong>：这个IP地址可以和另一个IP地址<strong>通信</strong>吗？这种类型的策略传统上由网络防火墙强制执行。</p></li><li><p style="margin-top: 5px;"><strong>程序执行</strong>：这个用户可以加载并<strong>执行</strong>这个未知的应用程序吗？此类策略传统上由防病毒软件和应用程序白名单软件强制执行。</p></li><li><p style="margin-top: 5px;"><strong>用户访问</strong>：此用户可以<strong>访问</strong>此内容吗？这种类型的策略传统上由访问控制机制强制执行。</p></li><li><p style="margin-top: 5px;"><strong>输入验证</strong>：这个<strong>输入</strong>可以被这个应用程序<strong>接受</strong>吗？这种类型的策略传统上由应用程序防火墙（例如WAF或数据库防火墙）强制执行。</p></li></ul><section style="margin-top: 15px;white-space: normal;"><strong>上下文感知</strong>。对应于图中的每一层，都有各层的上下文，通过感知各层的上下文，如<strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">应用程序感知</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">、</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">身份感知</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">、</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">内容感知</strong><strong>、流程感知</strong>，可以<span style="text-align: center;">将上下文添加到安全决策的输入中，从而做出更加正确的安全操作决策</span>。</section><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">范式转变：<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong><strong><strong><strong><span style="text-align: center;"><strong><strong style="text-align: left;">信任度量</strong></strong></span></strong></strong></strong></strong>需要实时上下文</strong></span></strong></span></strong></strong></strong></strong></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="white-space: normal;"><strong>1）基础设施转变：从静态</strong><strong>IT基础设施转向动态<strong style="white-space: normal;">IT基础设施</strong></strong><br/></p><section style="margin-top: 15px;"><strong style="white-space: normal;">静态业务和IT基础设施</strong>。当业务和IT基础设施相当静态且明确时，企业<strong>拥有和控制</strong><span style="color: rgb(0, 0, 0);">图5</span>中的大部分实体，所以网络安全<strong>策略执行点</strong>（如防火墙、邮件安全网关）通常只放置在企业拥有的东西（因此信任）和企业不拥有的东西（因此不信任）之间的<strong>分界点（边界</strong><strong>）</strong>。</section><section style="margin-top: 15px;"><strong>绝对信任模型。</strong>这种<strong>信任“我们”</strong>（我们拥有它并且控制它）而<strong>不信任“他们”</strong>（他们拥有它并且控制它）的安全模型，就是<strong style="white-space: normal;">绝对信任模型</strong>。</section><section style="margin-top: 15px;"><strong>动态业务和IT环境</strong>。业务和IT领域的多种<strong>融合趋势</strong>，正在打破传统静态IT基础设施和业务的边界，正在形成越来越动态的业务和IT环境：<br/></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>移动化。</strong>意味着随时随地使用“可信度”不同的设备（并非都归企业所有）从不同地点访问企业的系统。</p></li><li><p><strong>外部协作化。</strong>意味着向外界开放企业的 IT 系统。访问内部系统的外部用户会越来越多，甚至多于内部员工。</p></li><li><p><strong>虚拟化。</strong>意味着工作负载和信息将不再与特定设备和固定IP地址绑定，从而打破基于物理属性的静态安全策略。</p></li><li><p><strong>云计算。</strong>意味着企业不再拥有或控制保存和处理企业的工作负载和信息的基础设施或应用程序。</p></li><li><p><strong>黑客产业化。</strong>意味着黑客从大规模攻击转向针对性攻击。导致企业对内部用户和系统的信任度降低。<br/></p></li></ul><section style="margin-top: 15px;white-space: normal;"><strong><strong style="white-space: normal;">绝对信任的丧失</strong></strong>。在动态的业务和IT环境中，企业无法预测访问系统和内容的所有需求。试图预先确定所有可能的使用场景，并使用静态的、预定义的安全策略来执行它们，无法提供企业所需的扩展性和灵活性。在动态IT基础设施的世界中，<strong style="white-space: normal;">绝对信任</strong>模型失败了。</section><section style="white-space: normal;margin-top: 25px;"><strong>2）安全范式转变：从绝对信任到信任度量</strong><br/></section><section style="white-space: normal;margin-top: 15px;">IT基础设施从静态向动态的转变，促使安全范式从绝对信任转向信任度量。与可以提前预先定义的<span style="color: rgb(0, 0, 0);">非黑即白的</span><strong>二元静态决策</strong>不同，新兴IT环境中的安全决策难以明确定义和事前预知。<strong>IT技术栈的每个元素，都需要以一定程度的不确定性对待</strong>。<strong>绝对</strong><strong style="text-align: left;white-space: normal;">信任（即<strong style="white-space: normal;text-align: left;">二元</strong>信任）将被“信任度量”范式所取代</strong><span style="text-align: left;">。</span></section><section style="white-space: normal;margin-top: 15px;">我们必须抛弃<strong style="white-space: normal;">幻想的绝对信任</strong>（实际上我们从未真正拥有过这种信任），将转向一种<strong>信任度</strong><strong>量</strong>的范式，即<strong>上下文感知的安全策略执行机制</strong>——它可帮助我们回答真正的问题：“我是否对相关实体有足够的信任，可以在我目前的风险承受能力水平和上下文中，<span style="color: rgb(0, 0, 0);">执行所请求的操作？”</span></section><p style="margin-top: 25px;"><strong>3）不可或缺：信任度量需要实时上下文</strong></p><section style="margin-top: 15px;">为了能够更快、更准确地度量信任级别，评估是否应该允许或拒绝给定的操作，我们<strong>必须在做出安全决策时</strong><strong>纳入更多实时上下文信息</strong>。<strong>这是上下文感知安全的核心</strong>。</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">五彩纷呈：安全上下文的类型和来源</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;"><span style="color: rgb(0, 0, 0);"><strong>1）安全上下文的类型</strong></span></section><section style="margin-top: 15px;white-space: normal;">除了经常使用的<span style="color: rgb(0, 0, 0);">环境上下文（如位置和时间）</span>，还有多种类型的上下文信息，可用于改进安全决策。图5中显示的任何层，都可以为改进安全决策提供额外的上下文。下表罗列了各个层中的上下文示例：<br/></section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-backh="1125" data-backw="550" data-ratio="2.0454545454545454" style="width: 100%;" data-type="png" data-w="550" src="https://wechat2rss.xlab.app/img-proxy/?k=940cf2bf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5U0bjKwnDJ4dIFRlsCdcpD4651ZFFvmlbrAu9Yf34hIF95jHIDuyibTQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;text-align: center;">表6-与安全决策相关的上下文示例</section><section style="margin-top: 15px;">所有这些层——环境、社区、流程、内容、身份、应用程序、操作系统、设备和网络——都<strong>可以为它们<span style="color: rgb(172, 57, 255);">下面的层</span>中做出的实时安全决策，提供有用的上下文</strong>。例如，身份级别和应用程序级别的信息，可以为网络级别的防火墙决策提供额外的上下文。内容级信息可以为决定是否允许通过电子邮件发送文档提供额外的上下文。<br/></section><p style="margin-top: 25px;"><strong style="color: rgb(0, 0, 0);white-space: normal;">2）安全上下文的来源</strong></p><section style="margin-top: 15px;text-align: left;">想用好上下文，除了知道有什么上下文，还要知道从哪里获取这些上下文。下表总结了一些常见上下文的来源（即获取方式）：</section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.959412780656304" data-w="1158" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fcb91db4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5tFzic5LLtp31iaciae8ncH0ofjQTWX3jxUCP5s4nuwoicPrLaY0JNIlAxw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;text-align: center;">表7-上下文的类型和来源</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">展望未来：上下文的未来是图谱化</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;"><strong>1）<strong style="white-space: normal;">上下文的未来是图谱化</strong></strong></section><section style="margin-top: 15px;">在安全世界中，<strong>威胁</strong><strong>情报</strong>显然是<strong>上下文</strong>的重要组织部分（参见表7中的“<strong>威胁上下文</strong>”）。而在很多语境中，<strong>情报</strong>就是上下文。</section><section style="margin-top: 15px;white-space: normal;">笔者明确看到了主流安全情报产品的图谱化趋势，从而给出断言：<strong>（大规模）</strong><strong>上下文的未来是图谱化</strong>。</section><section style="margin-top: 15px;white-space: normal;"><strong>图谱为何如此重要？</strong>因为<strong>图谱含有</strong><span style="color: rgb(172, 57, 255);"><strong>语义</strong></span><span style="color: rgb(0, 0, 0);">(语言有意义，容易被理解)</span>，是<strong>最高层次</strong>的信息表达方式。<strong style="white-space: normal;">图谱以类似</strong><span style="color: rgb(172, 57, 255);"><strong style="white-space: normal;">人类大脑</strong></span><strong style="white-space: normal;">的方式</strong>，组织各种实体和上下文知识。对于海量信息中的知识探索和发现活动，图谱无疑是最值得期待的工具。图谱采取<strong>用图说话</strong>的<strong>可视化方法</strong>，将上下文的易用性提升到新的高度，为降低威胁调查、行为异常、隐私合规等安全技术的门槛提供了可能。</section><section style="margin-top: 15px;white-space: normal;"><strong>图谱的难度很大</strong>。也许有人会说：图谱的应用门槛没多高！但笔者想提醒的是：<span style="color: rgb(172, 57, 255);"><strong>关系</strong></span><strong>之中见精髓，</strong><span style="color: rgb(172, 57, 255);"><strong>规模</strong></span><strong>之上见工</strong><strong>夫</strong>。实体和关系的<strong style="white-space: normal;"><strong style="white-space: normal;">建模</strong><strong style="white-space: normal;">方式</strong>、规模量级、丰富程度</strong>，图谱的<strong>易用性</strong>、<strong>探索性</strong>、<strong>启发性</strong>，无不是横亘在图谱面前的<strong>巨大挑战</strong>。实际上，图谱与图论、本体论、自然语言处理、神经网络、人工智能等前沿理论关系紧密。<br/></section><section style="margin-top: 15px;white-space: normal;">贫穷会限制想象力。要做好自己的图谱，还是应该先看看别家的图谱。<br/></section><p style="white-space: normal;text-align: left;margin-top: 25px;"><span style="text-align: center;"><strong style="text-align: left;"><span style="text-align: center;">2）VirusTotal图谱</span></strong></span><span style="text-align: center;"><strong style="text-align: left;"><span style="text-align: center;"></span></strong></span></p><section style="margin-top: 15px;white-space: normal;text-align: left;"><span style="text-align: center;">VirusTotal</span>称：“<span style="color: rgb(172, 57, 255);"><strong>上下文是王道</strong></span>（Context is king）”。可见其对上下文之重视。</section><section style="margin-top: 15px;white-space: normal;text-align: left;"><span style="text-align: center;">Virus</span><span style="text-align: center;">Total</span>认为：你不能仅仅依靠“一枚子弹”（即一个样本）或“一块拼板”（即你的本地数据），来与全球范围内的攻击者进行战斗。你需要有持续跟踪恶意活动的“<strong>整部电影</strong>”，必须有<strong>尽量完整的上下文</strong>。<strong><span style="text-align: center;">Virus</span><span style="text-align: center;">Total图谱</span>（<span style="text-align: center;">Virus</span><span style="text-align: center;">Total</span> Graph）正是你的救星</strong>。</section><section style="margin-top: 15px;white-space: normal;text-align: left;"><strong><span style="text-align: center;">Virus</span><span style="text-align: center;">Total图谱</span></strong>充分利用各种<strong>实体</strong>的<strong>属性</strong>和<strong>关系</strong>，以可视化方式，浏览或搜索<span style="text-align: center;">Virus</span><span style="text-align: center;">Total</span>的海量数据集，高效执行安全事件和威胁的<strong>调查</strong>。如下图所示：</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.8846560846560847" data-w="945" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d684ba82&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5lJxOo6fHwGnzvicOcW7yyWqMF0ibDeia6xgPExvDkq6Mic6rWguT04Y8jg%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图8-VirusTotal<span style="text-align: justify;">图谱的调查示例</span></section><p style="margin-top: 25px;"><strong>3）CrowdStrike</strong><strong><span style="text-align: center;">威胁图谱</span></strong><br/></p><section style="margin-top: 15px;"><strong style="white-space: normal;"><span style="text-align: center;"></span></strong></section><section style="margin-top: 15px;"><span style="text-align: center;"></span>CrowdStrike将<strong><span style="text-align: center;">威胁图谱</span></strong><span style="text-align: center;">（Threat Graph）</span>视为自己的<strong>云端安全大脑</strong>。CrowdStrike声称自己是第一个有目的地使用<strong><span style="color: rgb(172, 57, 255);">图数据库</span></strong>来实现网络安全的公司，并基于图数据库构建了<strong><span style="text-align: center;">威胁图谱</span></strong><span style="text-align: center;">。</span></section><section style="margin-top: 15px;"><span style="text-align: center;"></span></section><section style="margin-top: 15px;"><span style="text-align: center;"></span></section><section style="margin-top: 15px;">正是利用了图数据模型，威胁图谱得以每天处理数十亿个事件，处理来自数百万个传感器的数据流，支持每秒50万个事件写入，并在纷繁复杂中快速发现威胁踪迹。<strong style="white-space: normal;"></strong></section><section style="margin-top: 15px;text-align: center;"><strong><strong><img class="rich_pages wxw-img" data-ratio="0.8324324324324325" data-w="925" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d17c00f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP59mgfHceL9FFRGXyqASNqdQAjEEiaJOPHhSr2DejVH9PXlk7ITAendVA%2F640%3Fwx_fmt%3Dpng"/></strong></strong></section><section style="margin-top: 15px;text-align: center;">图9-CrowdStrike威胁图谱（Threat Graph）</section><p style="white-space: normal;margin-top: 25px;"><strong>4）<span style="text-align: center;">Recorde</span><span style="text-align: center;">dFuture</span></strong><strong><span style="text-align: center;"><strong style="white-space: normal;">安全情报图谱</strong></span></strong></p><section style="margin-top: 15px;"><span style="text-align: center;">RecordedFuture</span>称：<strong>安全情报图谱<span style="text-align: center;">（Security Intelligence Graph）</span></strong>代表了<span style="text-align: center;">RecordedFuture</span>用来完成使命的<span style="color: rgb(172, 57, 255);"><strong>方法论</strong></span>和专利技术。安全情报图谱用于指导人类分析师和算法的分析过程。</section><section style="margin-top: 15px;"><span style="text-align: center;">Recorde</span><span style="text-align: center;">dFuture<span style="text-align: center;">安全情报图谱</span>综合了各种各样的情报信息，如下图所示：</span></section><section style="margin-top: 15px;text-align: center;"><strong style="text-align: center;"><strong><img class="rich_pages wxw-img" data-ratio="1.0219594594594594" data-w="592" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b3f84e68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5SgZWWLoAqydzg2X6VQTvS30y1gGFzY5ibXUExCG69yaMFfLXD2XkuNg%2F640%3Fwx_fmt%3Dpng"/></strong></strong><br/></section><section style="margin-top: 15px;text-align: center;">图10-RecordedFuture安全情报图谱的信息<strong><strong style="white-space: normal;"></strong></strong></section><section style="margin-top: 15px;white-space: normal;">安全情报图谱连接了<strong>数十亿个实体</strong>，通过<strong>本体</strong>和<strong>事件</strong>，<strong>映射</strong>网络安全领域中的各种<strong>复杂关系</strong>。如下图所示：<br/></section><section style="margin-top: 15px;white-space: normal;"><img class="rich_pages wxw-img" data-ratio="0.5737211634904714" style="text-align: center;" data-type="png" data-w="997" src="https://wechat2rss.xlab.app/img-proxy/?k=9419c759&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMCpVtgtxOpIeH0uQSbrdP5k53Sah0Yqf6HPice1GvucKaE2WK5niafcrBTHIp6ibn94mnGeHRm2b1lA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;text-align: center;">图11-RecordedFuture安全情报图谱的原理</section><p style="text-align: left;margin-top: 25px;"><strong>5）Securiti 个人数据图谱（People Data Graph）</strong></p><p style="text-align: left;margin-top: 15px;">上面展示的都是威胁情报图谱，而Securiti构建了一个与<strong>身份</strong>和<strong>数据</strong>相关的图谱——<strong style="text-align: left;white-space: normal;">个人数据图谱（PDG，People Data Graph）</strong>。<strong style="text-align: left;white-space: normal;"></strong><br/></p><section style="margin-top: 15px;">Securiti是一家数据安全和隐私保护公司，是<strong>RSAC 2020创新沙盒的</strong><span style="color: rgb(172, 57, 255);"><strong>冠军</strong></span>。<span style="text-align: left;">PDG是Securiti</span>实现<strong style="text-align: left;"><span style="text-align: justify;">现代隐私运营(PrivacyOps)框架</span></strong>的基础技术。</section><section style="margin-top: 15px;">PDG可以跨系统地连接到云中和本地、结构化和非结构化的异构数据源，自动发现和构建个人数据与所有者之间的关系图谱，从而<span style="text-align: left;">为隐私合规奠定了坚实基础。</span></section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.9120603015075377" data-w="1194" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=27c1683d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPN7ky9DPib6bJ2Rz5KQZFhWiciaicUkGmQGQCt4I0bf4Sdn98jCIiaupbeMXVmCMWllbrU68Q9ibubmSTFA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;text-align: center;"><span style="text-align: center;">图12-个人数据图谱（PDG）</span></section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">07</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">最终陈述：安全的未来是安全云</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="white-space: normal;"><strong>安全的未来是（实时）上下文</strong>。<strong style="white-space: normal;">上下文感知安全机制提供了安全策略的抽象和自动化层</strong>。<strong>上下文感知</strong>有助于使安全成为动态业务需求的推动因素，而不是阻碍因素。企业安全解决方案应该具备越来越强的<strong>上下文感知能力</strong>。</p><section style="margin-top: 15px;white-space: normal;"><strong style="white-space: normal;">安全的未来在云端</strong>。如果<strong>安全的未来是上下文</strong>，得到的下一个推论就是：<strong>安全的未来在云端</strong>。因为<strong>孤岛式、分散式</strong>的上下文是非常低效的，也不具备共享和扩散的价值。安全上下文需要<strong>集中化、规模化、图谱化</strong>，而只有<strong>云化</strong>才能承载这样的要求。</section><section style="margin-top: 15px;white-space: normal;"><strong style="white-space: normal;">安全的未来是SaaS化</strong>。如果<strong style="white-space: normal;">安全的未来在云端</strong>，得到的下一个推论就是：<strong>安全的未来是SaaS化</strong>。虽然很多人都会争论说，<strong>SaaS只适合中小客户，并不适合大型客户</strong>。但笔者觉得，恰当的说法是：<span style="color: rgb(172, 57, 255);"><strong>仅有SaaS</strong></span><strong>，是不适合大型客户的</strong>。<strong style="white-space: normal;">大型客户的最佳策略</strong>应该修正为：<strong>客户本地化安全建设+厂商云化安全服务</strong>（如图13所示）。</section><section style="margin-top: 15px;white-space: normal;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">安全的未来是</strong></span></strong></span></strong></strong></strong></strong><span style="color: rgb(172, 57, 255);"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="color: rgb(172, 57, 255);text-align: center;"><strong><span style="color: rgb(172, 57, 255);text-indent: 34px;"><strong style="text-align: left;">安全云</strong></span></strong></span></strong></strong></strong></strong></span>。<strong style="white-space: normal;">安全是要花钱的</strong>。<strong style="white-space: normal;">我们不能平等地保护一切，我们所保护的一切也不是同等价值。</strong>网络安全预算不大可能以比整体IT预算更快的速度增长。预算和资源的限制，将迫使我们不断优化风险/回报比，并采取智能化的安全保护措施。这正是<strong>安全云</strong>的意义所在（如图13所示）。与其部署所有可能的安全控制措施，不如根据所请求操作的上下文（如受保护过程的重要性、所处理内容的敏感度、所涉及实体的信任度、客户的风险容忍度等），采取更加<strong style="white-space: normal;">智能化</strong>的控制措施。不论称之为“<strong style="white-space: normal;">基于信任</strong>”、“<strong style="white-space: normal;">基于风险</strong>”、“<strong style="white-space: normal;">基于度量</strong>”、“<strong>基于智能</strong>”的安全转型，<strong style="white-space: normal;">上下文感知都是最关键的促成因素</strong>。</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.7492774566473989" data-w="1384" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c3737b2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNnRwAbib85AVOiaoa8PQic1ZBhkicS91PtwRwbVCxN38TqBvawpCTJqgJQjNsKLnyP80YgbHbBPMcEbQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图13-CrowdStrike<strong>云化</strong>威胁图谱与<strong>纯本地化</strong>解决方案的成本比较</section><section style="margin-top: 15px;">CrowdStrike称：“<strong style="white-space: normal;">大数据、图谱、云</strong>是阻止当今威胁的三个关键。” 这三个关键，一个都不能少。而<strong>三者合在一起</strong>，就是CrowdStrike<strong style="white-space: normal;"><span style="text-align: center;">威胁图谱</span></strong><span style="text-align: center;">，</span>也正是笔者所说的“<span style="color: rgb(172, 57, 255);"><strong>安全云</strong></span>”。</section><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></section>



<p><a href="2247494638">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e607fa84&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494638%26idx%3D1%26sn%3D916311c9c461e000bb71ca7e1f6328f9%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 09 Mar 2022 05:30:00 +0800</pubDate>
    </item>
    <item>
      <title>美国国防部Thunderdome零信任原型正式启动</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494605&amp;idx=1&amp;sn=afb2a85787c674b569b5e484a28a3bf0</link>
      <description>这是DISA的一小步，也是DoD的一大步。</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2022-02-13 17:38</span> <span style="display: inline-block;"></span>
</p>

<p>这是DISA的一小步，也是DoD的一大步。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a18b9f8a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNicYumoKQLcgFuz4aHLHhvVlvqRoml9LwMPkGAvMTagrUJibahCtSwZYZslozVkFYibnBFmbCbibwUYw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<strong>40</strong><span style="color: rgb(0, 0, 0);"><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>6</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><strong><span style="font-size: 17px;">2022年</span></strong><span style="font-size: 17px;"><strong>1月24日</strong>，美国<span style="text-align: left;caret-color: rgba(0, 0, 0, 0);">国防信息系统局</span><span style="font-size: 17px;text-align: left;"><span style="text-align: left;caret-color: rgba(0, 0, 0, 0);">（<strong><span style="text-align: left;">DISA</span></strong></span><span style="text-align: left;caret-color: rgba(0, 0, 0, 0);"><span style="text-align: left;caret-color: rgba(0, 0, 0, 0);">）</span></span></span>向 Booz Allen Hamilton（以下简称<strong>BAH</strong>） 授予了一份价值 <strong>680万美元</strong>的合同，用于执行<strong>Thunderdome原型</strong>。这是自<strong>2021年5月发布</strong>Thunderdome<strong>信息请求</strong>和<strong>7月发布</strong><strong>方案白皮书请求</strong>（<strong>9月3日截止</strong>）以来，靴子终于落地的声音。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;"><span style="text-align: left;">DISA</span>称，Thunderdome是其<strong>最先进</strong>的</span><span style="font-size: 17px;color: rgb(172, 57, 255);"><strong>零信任安全和网络架构</strong></span><span style="font-size: 17px;">。这个断言意味着<strong>安全和网络的</strong></span><span style="font-size: 17px;color: rgb(172, 57, 255);"><strong>融合</strong></span><span style="font-size: 17px;">，也就是<strong>SASE</strong>（安全访问服务边缘）架构。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;">我们知道，<strong>完美的SASE架构通常要求网络重构</strong>。通常而言，一般企业并不愿意进行网络重构，因为重构的成本和挑战都太大了。以至于著名咨询机构Forrester给出了基本策略：应该先从容易干的<strong>零信任</strong><span style="text-align: left;">下手</span>，然后等到机会成熟了再去搞定难搞的<strong>网络重构</strong>。参见《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494421&amp;idx=1&amp;sn=de71ce596220df4a31a3f2eb86768cec&amp;chksm=97fa3673a08dbf650651a57ef7e717ecb1e73e47846669f6d26bdf0be00826bd605dad294f33&amp;scene=21#wechat_redirect" textvalue="戏说零信任和SASE——安全界的如来和大圣" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="font-size: 17px;color: rgb(0, 82, 255);text-decoration: underline;">戏说零信任和SASE——安全界的如来和大圣</span></a><span style="font-size: 17px;">》。甚至DISA的Thunderdome项目经理兼边界安全部门负责人 Angela Landress 也承认：虽然SASE已在大部分商业世界中实施，但<strong>尚未被政府广泛采用</strong>。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;">那么，作为世界上规模最大、网络最为复杂的美国国防部，为什么会下定决心要做出网络重构这一决策呢？</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;"><span style="text-align: left;">我们先看看官方的解释。DISA副局长Chris Barnhurst在新闻稿中表示：</span><span style="text-align: left;">向Thunderdome原型的迈进是“</span><strong style="text-align: left;white-space: normal;">国防部向下一代网络安全和网络架构的重大转变</strong><span style="text-align: left;">”，该工作“从根本上改变了我们传统的</span><strong style="text-align: left;white-space: normal;">以网络为中心</strong><span style="text-align: left;">的</span><strong style="text-align: left;white-space: normal;">纵深防御安全模式</strong><span style="text-align: left;">转变为</span><strong style="text-align: left;white-space: normal;">以数据保护为中心</strong><span style="text-align: left;">的模式。</span><span style="text-align: left;">”</span></span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;">笔者觉得，这种官方解释只是说出了<strong>正确的废话</strong>，并未点明要害。笔者以为，<span style="text-align: left;">美国国防部</span>狠下决心要做网络重构的最关键原因，就是要建立</span><span style="font-size: 17px;color: rgb(172, 57, 255);"><strong>下一代中间层安全</strong></span><span style="font-size: 17px;">。这是因为<strong>上一代中间层安全</strong>，即搞了十年的<strong>JRSS</strong>（联合区域安全栈），被批评为运行效率低下。关于</span><strong><span style="font-size: 17px;color: rgb(0, 0, 0);">中间层安全</span></strong><span style="font-size: 17px;color: rgb(0, 0, 0);">的含义，参见《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494017&amp;idx=1&amp;sn=cbebe869893bba17fdb798d2bb0965a0&amp;chksm=97fa34e7a08dbdf1104e434350b7c6effc6410e473c148c81435c0d423aa80a7ff1bfca3220d&amp;scene=21#wechat_redirect" textvalue="用零信任替代中间层安全？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="font-size: 17px;text-decoration: underline;color: rgb(0, 82, 255);">用零信任替代中间层安全？</span></a><span style="font-size: 17px;color: rgb(0, 0, 0);">》。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 17px;">DISA的决心是如此之强，以至于<span style="text-align: left;">DI</span><span style="text-align: left;">S</span><span style="text-align: left;">A</span>对<span style="text-align: left;">Thunderdome</span>的时间进度要求非常紧迫——只给了</span><strong>6个月时间！</strong>从1月24日算起，大概是到7月底。然后，再经过3至6个月的<strong>过渡期</strong>后，将于<strong>2023财年初开始进入生产阶段</strong>。<span style="text-align: left;">Thunderdome</span>是<strong>DISA的第一个零信任工作原型</strong>，该原型可能会在<strong>第四产业</strong>（含DISA<span style="text-align: left;">）</span>和<strong>海军</strong>开始实施，然后可<span style="text-align: left;">扩展</span>到整个国防部。</p><p style="text-align: left;margin-top: 10px;">DISA最擅长的事情就是为美国国防部及其全球作战人员<strong>构建、测试、验证、实施</strong>一流的网络安全解决方案。对于<span style="text-align: left;">Thunderdome</span>的后续发展，让我们拭目以待。</p></section></section></section></section></section><section style="margin-top: 15px;"><strong><span style="text-align: left;">关键词</span></strong><span style="text-align: left;">：<span style="caret-color: rgba(0, 0, 0, 0);"><span style="text-align: left;">DoD</span></span> (<span style="text-align: left;">美国国防部</span>) ；<span style="text-align: left;caret-color: rgba(0, 0, 0, 0);">DISA</span><span style="text-align: left;caret-color: rgba(0, 0, 0, 0);"> (国防信息系统局) ；<span style="text-align: left;">BAH（</span><span style="text-align: center;"><span style="text-indent: 34px;">Booz Allen Hamilton<span style="text-align: left;">）；JRSS（联合区域安全栈）；SASE（安全访问服务边缘）；</span></span></span></span>IDIQ(不定期限/不定数量)<span style="text-align: center;"><span style="text-indent: 34px;"><span style="text-align: left;">。</span></span></span></span></section><section style="text-align: center;margin-top: 15px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><section style="margin-top: 15px;">1.DISA授予Thunderdome合同<br/></section><p>2.Thunderdome的目标受众和推广策略</p><p>3.为何取名Thunderdome？</p><p>4.Thunderdome代表下一代网络和安全架构<br/></p><p>5.中标者BAH是何来历<span style="text-align: center;"></span></p><section style="text-align: left;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">DISA授予Thunderdome合同</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;"><br/></section><section style="margin-top: 15px;"><strong>前期方案征集</strong>。DISA于2021年5月发布关于<span style="text-align: left;">Thunderdome零信任方案的</span><strong style="text-align: left;white-space: normal;">信息请求</strong>，又于2021年7月发布关于<span style="text-align: left;">Thunderdome方案</span>的<strong style="text-align: left;white-space: normal;">白皮书请求</strong>，并于<strong>9月3日截止方案征集</strong><span style="text-align: left;">。<span style="text-align: left;">关于Thunderdome方案白皮书请求的内容，可参见《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494496&amp;idx=1&amp;sn=4898d7237fecce4e148941978a13be6d&amp;chksm=97fa3606a08dbf1027522a7a5574f347bede1f543ca588bd30366bdbb5a887c06701d0448c0e&amp;scene=21#wechat_redirect" textvalue="美国国防部零信任实施方案：Thunderdome（雷霆穹顶）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" style="white-space: normal;" data-linktype="2"><span style="text-align: left;text-decoration: underline;color: rgb(0, 82, 255);">美国国防部零信任实施方案：Thunderdome（雷霆穹顶）</span></a><span style="text-align: left;">》。</span></span><span style="text-align: left;">在8月中旬的时候，DISA已经收到了<strong>近60份</strong><span style="text-align: left;">Thunderdome</span>白皮书提案。</span></section><section style="margin-top: 15px;"><strong>当下合同授予</strong>。经过4个月之后，DISA于2022年<strong>1月24日</strong>向Booz Allen Hamilton（BAH）授予了一份价值<strong>680万美元</strong>的合同，用于执行Thunderdome原型。</section><p style="white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4548022598870056" data-s="300,640" data-w="1062" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a2ea16d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNicYumoKQLcgFuz4aHLHhvV9mKz7HZ58g52NVL2KIWUMwNQyTQ6VEZnvfCvBn2AkJAXn8ZXGD128Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="white-space: normal;text-align: center;">图1-DISA官宣Thunderdome原型合同授予</p><section style="margin-top: 15px;white-space: normal;text-align: left;">注：图中的副标题是“<strong>Thunderdome将是DISA最先进的零信任安全和网络架构</strong>”。</section><section style="margin-top: 15px;"><strong>合同周期是6个月</strong>。DISA的目标是在6个月内生产一个<strong style="white-space: normal;">可在整个国防部扩展</strong>的工作原型。</section><section style="margin-top: 15px;"><strong>后续推进</strong><strong>计划</strong>。<strong>原型阶段</strong>（即Thunderdome原型合同）仅仅持续六个月，然后经过3至6个月的<strong>过渡期</strong>后，将于2023财年初开始<strong>生产</strong>。<br/></section><section style="margin-top: 15px;"><strong><strong>Thunderdome</strong>的主要目标。</strong>DISA将通过利用SASE（安全访问服务边缘）和SD-WAN（软件定义广域网）等商业技术，测试如何实现DISA于2020年3月发布的<strong>国防部零信任参考架构</strong>（参见《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494400&amp;idx=1&amp;sn=9f76a4c3870447234c99619b78bbb9bb&amp;chksm=97fa3666a08dbf70a91949c87f409e8bbb43acc3cc4f04466e493c46e3fce5928ad36dd84bc8&amp;scene=21#wechat_redirect" textvalue="DISA发布国防部零信任参考架构" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">DISA发布国防部零信任参考架构</span></a>》）。DISA还想确定其初始零信任概念是否可以扩展到大规模的国防部企业，以及需要进行哪些调整来满足军事网络原则。</section><section style="margin-top: 15px;white-space: normal;"><strong>与美国联邦网络安全现代化工作保持一致。</strong>DISA的Thunderdome原型与美国联邦政府的多项网络安全现代化工作保持一致，实际上是针对这些政策或战略中的零信任要求，进行了呼应。包括：</section><ul class="list-paddingleft-2" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 5px;">美国总统关于<strong>改善国家网络安全</strong>的行政指令（即<strong>EO 14028</strong>）；</section></li><li><section style="margin-top: 5px;">国防部首席信息官 (DOD CIO) 的<strong>数字现代化战略：</strong>参见《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494029&amp;idx=1&amp;sn=5747d0ad2476c1e675db7ae40385c2da&amp;chksm=97fa34eba08dbdfde465509b21a832fc6ecce0dff471a8217b00718c02c350335aa8ae40ca14&amp;scene=21#wechat_redirect" textvalue="美国国防部将JIE升格为DMS（数字现代化战略）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="text-decoration: underline;color: rgb(0, 82, 255);">美国国防部将JIE升格为DMS（数字现代化战略）</span></a>》；</section></li><li><section style="margin-top: 5px;"><strong>DISA战略计划：</strong>参见《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493971&amp;idx=1&amp;sn=b12176227a42a27b4f024b191086dbc5&amp;chksm=97fa3435a08dbd23a8b821c9e9b1f88ba276a9a15a75af79dfbfba921c1250e89870e9d66594&amp;scene=21#wechat_redirect" textvalue="DISA战略计划2.0版抬升零信任地位" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">DISA战略计划2.0版抬升零信任地位</span></a>》。</section></li></ul><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">Thunderdome的目标受众和推广策略</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong><strong>Thunderdome</strong>的目标受众。</strong>最终目标是整个国防部，但先从所谓的<strong>第四产业机构</strong>开始。所谓“<strong>第四产业</strong>”，主要是指国防部内<strong>除了军种和情报机构之外</strong>的<strong>国防机构</strong>和<strong>外勤机构</strong>（DAFA），<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">大概有<strong>二十多个机构</strong>，如</span><strong>国防部长办公室</strong>、<strong>联合参谋部</strong>、<strong>DISA</strong>、导弹防御局等。关于<strong style="white-space: normal;">第四产业</strong>的具体范围，可参见《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493985&amp;idx=1&amp;sn=2e06682adae40ae94da87b218e32d683&amp;chksm=97fa3407a08dbd111398b8a0a9b1a59cf2ebde72638f824907b15d927e471c7655225b8c36b6&amp;scene=21#wechat_redirect" textvalue="美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">美国国防部IT改革的“皇冠宝石”：DES（国防飞地服务）</span></a>》。Thunderdome项目的<strong>任务合作伙伴</strong>包括海军、陆军、空军。其中，<strong>海军</strong>将率先开始实施Thunderdome能力，因为他们表现出最大的兴趣。</section><section style="margin-top: 15px;white-space: normal;"><strong>为何Thunderdome要从第四产业开始？</strong>笔者推测有两个原因：一是第四产业可能是国防部中<strong>IT成熟度相对比较高</strong>的机构（与各作战部队相比），已经具备了标准化的前提条件；二是早期国防部首席信息官和DISA的联合审查，显示了第四产业“<strong>令人大开眼界的低效率</strong>”。较高的IT成熟度+极低的运行效率，使得第四产业成为Thunderdome的首个试验田。<strong style="white-space: normal;"></strong><br/></section><section style="margin-top: 15px;"><strong>Thunderdome不具有强制性</strong>。Thunderdome并非国防部的唯一零信任解决方案。DISA不打算强制国防部或军种使用Thunderdome方案。这意味着军种可以选择与DISA合作或实施自己的零信任方案。<br/></section><section style="margin-top: 15px;"><strong>DISA推广<strong style="white-space: normal;">Thunderdome</strong>的策略</strong>。DISA的思路是让Thunderdome变得足够好，然后<strong>吸引</strong>各军事部门采用Thunderdome。DISA新兴技术部负责人Stephen Wallace（是DISA推行零信任理念的关键人物）表示：如果其它部门看到Thunderdome的价值，自然就会采用它；而如果其它部门想走自己的路，那也没关系。但<strong>DISA确实担心各走各的路</strong>，其中特别值得担心的就是由此导致的<strong>互操作性问题</strong>。</section><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">为何取名Thunderdome</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>Thunderdome的能力</strong>。Thunderdome共有七项能力，与<strong>国防部的七大零信任支柱</strong>相一致，包括用户、设备、网络、应用程序、数据、可见性与分析、自动化与编排。同时，Thunderdome具有显著的<strong>SASE</strong>(安全访问服务边缘)特征，包含<strong>SD-WAN</strong>(软件定义区域网络)功能。</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.39351851851851855" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c12c37ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOgg3KYFqz1B8YU6m3dAkJSYXzN4gqLdf4kycicVuNS6Kevoq9c2ZiadJB8yabmuYuMg90wvWrfadbQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图2-<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">国防部零信任实施框架</span><br/></section><section style="margin-top: 15px;white-space: normal;">笔者在之前的<span style="text-align: left;">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494496&amp;idx=1&amp;sn=4898d7237fecce4e148941978a13be6d&amp;chksm=97fa3606a08dbf1027522a7a5574f347bede1f543ca588bd30366bdbb5a887c06701d0448c0e&amp;scene=21#wechat_redirect" textvalue="美国国防部零信任实施方案：Thunderdome（雷霆穹顶）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="text-align: left;white-space: normal;"><span style="text-decoration: underline;color: rgb(0, 82, 255);">美国国防部零信任实施方案：Thunderdome（雷霆穹顶）</span></a><span style="text-align: left;">》</span>中，揣测了Thunderdome的含义&#34;<strong>雷霆穹顶</strong>&#34;。</section><section style="margin-top: 15px;white-space: normal;">现在，笔者找到了<strong>准确的解释</strong>：Thunderdome的灵感来自于——从<strong>建筑学</strong>的角度来看，<strong>圆顶</strong>比传统建筑<strong>更轻</strong>、<strong>更快</strong>，也是<strong>最坚固</strong>的设计之一。因为圆顶可以<strong>均匀地支撑屋顶的重量</strong>，所以没有哪个点支撑整个负载或在压力下屈服。</section><section style="margin-top: 15px;white-space: normal;">DISA官员们表示，这恰好反映了<strong>Thunderdome想要实现的零信任状态，即</strong><strong>其所包含的许多零信任概念，需要相互协同工作，为基于云的实现创建了一种强大、高效、架构合理的方法</strong>。</section><section style="margin-top: 15px;white-space: normal;">所以，笔者之前将其翻译为&#34;<strong>雷霆穹顶</strong>&#34;还是相对准确的。</section><p style="margin-top: 15px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">Thunderdome代表<strong style="white-space: normal;">下一代网络和安全架构</strong></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><p style="margin-top: 10px;white-space: normal;text-align: left;"><strong>Thunderdome</strong><strong>的价值究竟在哪里？</strong>以笔者看来，主要是<strong>以SASE取代JRSS</strong>，成为<strong>下一代网络和安全架构</strong>，也是<strong>下一代中间层安全</strong>。<strong style="text-align: left;white-space: normal;">SASE</strong>架构既包含了<strong>网络与安全的融合</strong>，又需要<strong>对复杂网络的整体重构</strong>。这对于美国国防部而言，绝对是颠覆性的。</p><section style="margin-top: 15px;white-space: normal;"><strong style="text-align: left;">以SASE取代JRSS</strong>。笔者曾在<strong>2021年1月</strong>的微信《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494017&amp;idx=1&amp;sn=cbebe869893bba17fdb798d2bb0965a0&amp;chksm=97fa34e7a08dbdf1104e434350b7c6effc6410e473c148c81435c0d423aa80a7ff1bfca3220d&amp;scene=21#wechat_redirect" textvalue="美军网络安全 | 用零信任替代中间层安全？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">用零信任替代中间层安全？</span></a>》中，以标题中的<strong>疑问号&#34;?&#34; </strong>提出了这个替代性问题。但当时，笔者以为是用<strong>SDP(软件定义边界)</strong>来替代JRSS。直到<strong>2021年7月</strong>，DISA开始发布<strong>Thunderdome白皮书请求</strong>，明确<strong>以Thunderdome取代JRSS</strong>。笔者才确定，DISA是要以<strong>SASE</strong>来替代JRSS。之后，DISA积极制定国防部范围的战略，使得任务合作伙伴可以从当前的网络安全解决方案（如JRSS）过渡到Thunderdome或其他零信任方案。而为期6个月的Thunderdome原型设计，将产生从JRSS过渡到Thunderdome方案的整体实施战略。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>何谓“中间层安全”？</strong>无论JRSS还是SASE，都是DISA口中的中间层安全。只不过，JRSS是上一代中间层安全，SASE是下一代中间层安全。JRSS可以参考《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247492610&amp;idx=2&amp;sn=4ebdd334b64094a16d24fdac9c8c2803&amp;chksm=97fa3964a08db072610f8c9fdaf07e6655328b680fb2c6fdb9a61b9c172438ad5e75c0313f94&amp;scene=21#wechat_redirect" textvalue="美军网络安全 | 第7篇：JIE（联合信息环境）启示和综述" linktype="text" imgurl="" imgdata="null" data-itemshowtype="11" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">美军网络安全 | 第7篇：JIE（联合信息环境）启示和综述</span></a>》中的JRSS章节。</section><section style="margin-top: 15px;white-space: normal;"><strong>超越</strong><strong>纵深防御安全模型</strong>。DISA副局长Chris Barnhurst说，“ Thunderdome反映了国防部向下一代网络安全和网络架构的重大转变”  “<strong>扎根于身份</strong>和增强的安全控制，Thunderdome 从根本上改变了我们传统的以网络为中心的<strong>纵深防御安全模型</strong>，以保护数据为中心，最终将通过采用零信任原则为国防部提供更安全的运行环境。” </section><section style="margin-top: 15px;"><strong>SASE落地的挑战性不会太大</strong>。Thunderdome项目经理Angela Landress女士认为：由于SASE是一种成熟的商业能力，因此使其适应DISA的需求应该不会太具有挑战性。“但我们需要对其进行一些设计，以便将其与 ICAM（身份、凭证和访问管理）、虚拟安全栈、SD-WAN集成。我认为我们将找到一些真正创新的解决方案，以在像 DISA这样的复杂网络上实施SASE。” <br/></section><section style="margin-top: 15px;"><strong>互操作性可能是最大的挑战</strong>。但DISA会直面该挑战，在一开始而非最终，就努力找出解决此问题的方法。为了帮助缓解这种挑战，DISA打算鼓励使用<strong>一套通用的标准、协议、分类法</strong>，以便将一切联系在一起，并与DISA的任务合作伙伴（即海、陆、空军）无缝合作。</section><section style="white-space: normal;text-align: left;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">中标者BAH是何来历</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;"><br/></p><p style="margin-top: 15px;">由于并未透露其它的投标方，也没透露任何投标方案，所以没法知道DISA为何选择BAH。笔者只能查阅BAH的官网资料，来寻找端倪。</p><p style="margin-top: 15px;">BAH公司<strong>成立于1914年</strong>。BAH是一家领先的<strong>专业服务公司</strong>，在<strong>管理、技术、咨询、工程领域</strong>提供广泛的服务和解决方案。<strong>100多年来</strong>，军方、政府、商界领袖都求助于BAH来帮助组织进行<strong style="white-space: normal;">转型</strong>，解决他们<strong>最复杂</strong>的问题。</p><p style="margin-top: 15px;">截至2021年12月31日，BAH的全球总部位于<strong>美国</strong>弗吉尼亚州麦克莱恩，在全球拥有约 <strong>29,500 名员工</strong>。截至2021年3月31日的<strong>12个月收入为 79 亿美元</strong>。要了解更多信息，请访问 www.boozallen.com。（纽约证券交易所代码：BAH）</p><p style="margin-top: 15px;"><strong>BAH支持美国国防部的历史悠久</strong>，自1940年公司赢得第一份海军合同以来，这一历史已超过 75 年。</p><p style="margin-top: 15px;"><strong>作为美国国防部 (DOD) 的首要数字集成商</strong>，BAH将数十年的任务经验与最先进的人工智能/机器学习 (AI/ML)、下一代数据解决方案、网络、网络空间、高级软件开发相结合，提供了卓越的交付能力。</p><p style="margin-top: 15px;"><strong>BAH近三分之一的专家是</strong><span style="color: rgb(172, 57, 255);"><strong>退伍军人</strong></span>，再加上数十年为军队提供服务的经验，可以确保其解决方案在现实中有效——而不仅仅是在实验室中。</p><p style="margin-top: 15px;">BAH正在加速创新以帮助保卫国家（如下图所示）：</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><section style="margin-top: 5px;">加速决策优势；</section></li><li><section style="margin-top: 5px;">赋能未来战士；</section></li><li><section style="margin-top: 5px;">推动国防未来。</section></li></ul><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6809864757358791" data-s="300,640" style="" data-type="png" data-w="1257" src="https://wechat2rss.xlab.app/img-proxy/?k=31c28471&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNicYumoKQLcgFuz4aHLHhvVDyKZ9d9UDkFPlRkgQ2oibAaUxnb6PT9F4ASPJxnRtIMbXtiakKr5icPxg%2F640%3Fwx_fmt%3Dpng"/></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3706015891032917" data-s="300,640" style="" data-type="png" data-w="1762" src="https://wechat2rss.xlab.app/img-proxy/?k=dad44d9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNicYumoKQLcgFuz4aHLHhvVQgBK6R91B1SXZYxKGoy60X4zNcrPfNFImZficrtJJtayILFlBSsMcjQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3779795686719637" data-s="300,640" style="" data-type="png" data-w="1762" src="https://wechat2rss.xlab.app/img-proxy/?k=dc019196&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNicYumoKQLcgFuz4aHLHhvV3pN2yiaHxAm88Y9evdqWs9stDxu4UPWlIk6vuYDvqdjcG5e4X2dhxpw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 15px;">笔者还在BAH官网上查到了一些<strong>亿美元级</strong><strong>别</strong>的<strong>军方合同</strong>：</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><section style="margin-top: 5px;">2016年，BAH被美国<strong>国防部</strong> (DoD) 评选为一份<strong>为期5年、价值50亿美元</strong>的<strong>IDIQ</strong>(不定期限/不定数量)合同的主要获奖者，该合同专注于<strong>网络安全和信息系统支持</strong>。<br/></section></li><li><section style="margin-top: 5px;">2018年，BAH获得<strong>DISA</strong>授予的一份<strong>为期10年、价值175亿美元</strong>的IDIQ合同，以提供<strong>信息和通信系统IT解决方案</strong>。</section></li><li><section style="margin-top: 5px;">2018年，BAH获得美国<strong>陆军</strong>工程兵团授予的一份<strong style="white-space: normal;">为期10年、</strong><strong>价值9亿美元</strong>的IDIQ合同，为国防部<strong>联合测试和评估计划(JT&amp;E)</strong>提供技术支持。<br/></section></li><li><section style="margin-top: 5px;">2020年，BAH获得美国总务管理局 (<strong>GSA</strong>) 和美国<strong>国防部</strong>授予的一份<strong>为期5年、价值8亿美元</strong>的合同，为美国国防部的联合人工智能中心(<strong>JAIC</strong>)提供<strong>人工智能（AI）服务</strong>。</section></li><li><section style="margin-top: 5px;">2020年，BAH成为美国<strong>空军</strong>授予的一份价值<strong>9.5亿美元</strong>的IDIQ合同的几个获奖者之一，以支持<strong>高级战斗管理系统(</strong><strong>ABMS)</strong>的开发，从而实现国防部联合全域指挥与控制 (<strong>JADC2</strong>) 。<br/></section></li></ul><p style="margin-top: 15px;">令人意外的是，最近被授予的Thunderdome原型合同，未能在BAH官网上查到。或许是680万美元的金额对BAH而言还不够大吧。</p><p style="margin-top: 15px;"><br/></p><p style="margin-top: 15px;">（本篇完）</p>



<p><a href="2247494605">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=87213657&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494605%26idx%3D1%26sn%3Dafb2a85787c674b569b5e484a28a3bf0%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 13 Feb 2022 17:38:00 +0800</pubDate>
    </item>
    <item>
      <title>《美国联邦政府零信任战略》正式版发布</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494558&amp;idx=1&amp;sn=24dbd295328876902a064e57eda63b7c</link>
      <description>春节前的问候</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2022-01-28 06:08</span> <span style="display: inline-block;"></span>
</p>

<p>春节前的问候</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=e3a6fcf8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNW0s67Z7ZtJAic0xLTjibFlsWFGYIvNcRP64m0BnjFIgmiaV8OticgicC5icbhWnibQibl1GymsdRHDqVMOw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<strong>30</strong><span style="color: rgb(0, 0, 0);"><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>8</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;">2022年1月26日，<span style="text-align: left;">美国</span><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">管理和预算办公室（OMB）</span></strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布《</span><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">联邦政府零信任战略》（Federal Zero Trust Strategy）</strong></span><span style="font-size: 16px;color: rgb(172, 57, 255);"><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">正式版</strong></span><span style="font-size: 16px;"><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">。</strong>这是继2021年9月7日<span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布《</span>联邦政府零信任战略》</span><span style="font-size: 16px;color: rgb(172, 57, 255);"><strong>草案</strong></span><span style="font-size: 16px;">之后的重要进展。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;"><strong style="font-size: 16px;text-align: left;white-space: normal;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">联邦政府零信任战略</strong>以<strong style="font-size: 16px;text-align: left;white-space: normal;color: rgb(172, 57, 255);">备忘录</strong>的方式发布，<span style="font-size: 16px;text-align: left;">备</span><span style="font-size: 16px;text-align: left;">忘录</span>的全称是：OMB <strong>M-22-09</strong>  <strong>《推动美国政府走向</strong><strong>零信任网络安全原则</strong><span style="font-size: 16px;text-align: left;">》</span>（Moving the U.S. Government Toward Zero Trust Cybersecurity Principles<span style="font-size: 16px;text-align: left;">）</span></span><span style="font-size: 16px;"><span style="font-size: 16px;text-align: left;">。</span><strong style="text-align: left;white-space: normal;font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"></strong></span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;font-size: 16px;">在之前的微信文章</span><span style="text-align: left;font-size: 16px;color: rgb(0, 82, 255);"><strong>《</strong></span><span style="text-align: left;font-size: 16px;color: rgb(0, 82, 255);text-decoration: underline;">美国联邦政府零信任战略</span><span style="text-align: left;font-size: 16px;color: rgb(0, 82, 255);">》</span><span style="text-align: left;font-size: 16px;color: rgb(0, 0, 0);">中，</span><span style="font-size: 16px;text-align: left;"><span style="text-align: left;font-size: 16px;">笔者已经概述了<span style="letter-spacing: 0.544px;">《</span>联邦政府零信任战略》<span style="color: rgb(172, 57, 255);">草案</span>的</span>内容要点<span style="text-align: left;font-size: 16px;">。本文中，则主要对两个版本的目录结构进行了对比，解释了几个重要的变化，并展示了最大的变化——</span></span><span style="font-size: 16px;text-align: left;color: rgb(172, 57, 255);"><strong>任务矩阵</strong></span><span style="text-align: left;font-size: 16px;"><strong>（Task Matrix）</strong>。该任务矩阵对各个政府机构实施零信任的具体行动做出了<strong><span style="font-size: 16px;text-align: left;">计划</span>安排</strong>，体现了真正的<strong>推动力</strong>。</span></p><p style="margin-top: 10px;white-space: normal;text-align: left;"><span style="font-size: 16px;">本文件的PDF文档有<strong>29页</strong>，译文大概</span><strong style="font-size: 16px;">2万字</strong><span style="font-size: 16px;">。</span><span style="font-size: 16px;">原文链接：</span></p><p style="margin-top: 10px;white-space: normal;text-align: left;"><span style="font-size: 16px;"><a href="https://zerotrust.cyber.gov/federal-zero-trust-strategy/" target="_blank">https://zerotrust.cyber.gov/federal-zero-trust-strategy/</a></span></p></section></section></section></section></section><section style="margin-top: 15px;"><strong><span style="text-align: left;">关键词</span></strong><span style="text-align: left;">：<strong><span style="text-align: left;">OMB</span></strong>（<span style="text-align: left;">管理和预算办公室</span>）；<strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">CISA</span></strong><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">（</span><span style="text-align: left;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">网络安全和基础设施安全局）</span><span style="text-align: left;">；</span><span style="text-align: left;">GS</span><span style="text-align: left;">A</span><span style="text-align: left;">（总务管理局）</span>；MFA（多因素认证）；</span></section><section style="text-align: center;margin-top: 15px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><section style="margin-top: 15px;">1.目录对比<br/></section><p>2.内容差异</p><p>3.任务矩阵<br/></p><p><br/></p><section style="margin-top: 15px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7133377571333775" data-s="300,640" style="text-align: center;" data-type="png" data-w="1507" src="https://wechat2rss.xlab.app/img-proxy/?k=d3767176&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNW0s67Z7ZtJAic0xLTjibFlsJhM47APTRst8t5dJMHlVKic8uQOhXyOYXO7xOKwBPmZMyY2usiaRJL8w%2F640%3Fwx_fmt%3Dpng"/><br/></section><p style="text-align: center;">图1-《联邦政府零信任战略》（Federal Zero Trust Strategy）正式版发布的网站截图</p><p style="text-align: left;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">目录对比</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><p style="white-space: normal;margin-top: 15px;">以下是两个版本的目录。笔者分别使用<span style="color: rgb(0, 82, 255);">蓝色</span>和<span style="color: rgb(61, 167, 66);">绿色</span>，标记了<strong style="text-align: left;white-space: normal;">草案目录</strong>和<strong style="white-space: normal;">正式版目录</strong>的主要区别：<br/></p><section style="text-align: left;margin-top: 15px;"><strong>草案目录：<br/></strong></section><p>1. 概述</p><p>2. 目的</p><p>3. 目标</p><section style="text-indent: 0em;">    3.1 身份<br/></section><section style="text-indent: 0em;">        3.1.1 愿景</section><section style="text-indent: 0em;">        3.1.2 行动</section><section style="text-indent: 0em;">            1. 企业范围的身份</section><section style="text-indent: 0em;">            2. 多因素认证，抵御网络钓鱼</section><section style="text-indent: 0em;">            3. <span style="color: rgb(0, 82, 255);">面向公众的身份验证</span></section><section style="text-indent: 0em;">            4. <span style="color: rgb(0, 82, 255);">使用强口令策略</span></section><p>    3.2 设备</p><p>        3.2.1 愿景</p><p>        3.2.2 行动</p><p>            1. 盘点资产</p><p>            2. 政府范围的EDR（端点检测和响应）</p><p>    3.3 网络</p><p>        3.3.1 愿景</p><p>        3.3.2 行动</p><p>            1. 加密 DNS 流量</p><p>            2. 加密 HTTP 流量</p><p>            3. 加密电子邮件流量</p><p>            4. <span style="color: rgb(0, 82, 255);">围绕应用程序，分段网络</span></p><p>    3.4 应用</p><p>        3.4.1 愿景</p><p>        3.4.2 行动</p><p>            1. 应用安全测试</p><p>            2. 容易获得的第三方测试</p><p>            3. 欢迎应用漏洞报告</p><p>            4. 安全地使应用程序可访问互联网</p><p>            5. 发现可上网的应用程序</p><p>    3.5 数据</p><p>        3.5.1 愿景</p><p>        3.5.2 行动</p><p>            1. 联邦数据安全策略</p><p>            2. 自动化安全响应</p><p>            3. 审计对云中敏感数据的访问</p><p>            4. 及时获取日志</p><p>附录. 参考资料</p><p style="text-align: left;"><br/></p><section style="margin-top: 15px;white-space: normal;"><strong>正式版目录：</strong></section><p style="white-space: normal;">1. 概述</p><p style="white-space: normal;">2. 执行摘要</p><p style="white-space: normal;">3. 行动</p><p style="white-space: normal;">    3.1 身份</p><p style="white-space: normal;">        3.1.1 愿景</p><p style="white-space: normal;">        3.1.2 行动</p><p style="white-space: normal;">            1. 企业范围的身份系统</p><p style="white-space: normal;">            2. 多因素认证</p><p style="white-space: normal;">            3. <span style="color: rgb(61, 167, 66);"><strong>用户授权</strong></span></p><p style="white-space: normal;">    3.2 设备</p><p style="white-space: normal;">        3.2.1 愿景</p><p style="white-space: normal;">        3.2.1 行动</p><p style="white-space: normal;">            1. 盘点资产</p><p style="white-space: normal;">            2. 政府范围的EDR（端点检测和响应）</p><p style="white-space: normal;">    3.3 网络</p><p style="white-space: normal;">        3.3.1 愿景</p><p style="white-space: normal;">        3.3.1 行动</p><p style="white-space: normal;">            1. <strong><span style="color: rgb(61, 167, 66);">网络可见性和攻击面</span></strong></p><p style="white-space: normal;">            2. 加密 DNS 流量</p><p style="white-space: normal;">            3. 加密 HTTP 流量</p><p style="white-space: normal;">            4. 加密电子邮件流量</p><p style="white-space: normal;">            5. <span style="color: rgb(61, 167, 66);"><strong>企业范围的架构和隔离策略</strong></span></p><p style="white-space: normal;">    3.4 应用和<span style="color: rgb(61, 167, 66);"><strong>工作负载</strong></span></p><p style="white-space: normal;">        3.4.1 愿景</p><p style="white-space: normal;">        3.4.1 行动</p><p style="white-space: normal;">            1. 应用安全测试</p><p style="white-space: normal;">            2. 容易获得的第三方测试</p><p style="white-space: normal;">            3. 欢迎应用漏洞报告</p><p style="white-space: normal;">            4. 安全地使应用程序可访问互联网</p><p style="white-space: normal;">            5. 发现可访问 Internet 的应用程序</p><p style="white-space: normal;">            6. <span style="color: rgb(61, 167, 66);"><strong>不可变的工作负载</strong></span></p><p style="white-space: normal;">    3.5 数据</p><p style="white-space: normal;">        3.5.1 愿景</p><p style="white-space: normal;">        3.5.1 行动</p><p style="white-space: normal;">            1. 联邦数据安全策略</p><p style="white-space: normal;">            2. 自动化安全响应</p><p style="white-space: normal;">            3. 审核对云中敏感数据的访问</p><p style="white-space: normal;">            4. 及时获取日志</p><p style="white-space: normal;">    3.6 <span style="color: rgb(61, 167, 66);"><strong>OMB 政策对齐</strong></span></p><p style="white-space: normal;">            1. OMB M-21-07：IPv6 和零信任</p><p style="white-space: normal;">            2. OMB M-19-17：PIV 和非 PIV 身份验证器</p><p style="white-space: normal;">            3. OMB M-19-26 和 OMB M-21-31：网络检查的替代方案</p><p style="white-space: normal;">            4. OMB M-15-13：用于内部连接的HTTPS</p><p style="white-space: normal;">附录A. 参考资料</p><p style="white-space: normal;"><span style="color: rgb(0, 0, 0);">附录B. </span><span style="color: rgb(61, 167, 66);"><strong>任务矩阵</strong></span>（Task Matrix）</p><p style="white-space: normal;"><br/></p><p style="white-space: normal;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">内容差异</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="white-space: normal;margin-top: 15px;">经过对比，主要的发现是：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="white-space: normal;margin-top: 5px;"><strong>目录级别的差异并不大</strong>：差异反映在<span style="color: rgb(0, 82, 255);">蓝色</span>和<span style="color: rgb(61, 167, 66);">绿色</span>标记的地方；</p></li><li><p style="white-space: normal;margin-top: 5px;"><strong>文字级别有大量的变化</strong>：尽管如此，但很多的文字变化，要么是改变了描述方式，要么是移动了位置，并无实质性的变化。</p></li></ul><section style="text-align: left;margin-top: 15px;">总体上看，<strong>两个版本的差别并不大</strong>。比较显著的变化包括：<br/></section><section style="margin-top: 15px;">1）在<strong>身份支柱</strong>方面，草案中一再强调的<span style="color: rgb(172, 57, 255);"><strong style="text-align: left;white-space: normal;">单点登录</strong></span><strong style="text-align: left;white-space: normal;">（SSO</strong><span style="text-align: left;">）</span>，在正式版中被<strong>完全抹除</strong>。比如草案中的要求&#34;机构必须为机构用户建立<strong>单点登录 (SSO) 服务</strong>&#34;，在正式版中被替换成&#34;机构必须为机构用户采用<strong>集中式身份管理系</strong><strong>统</strong>&#34;。</section><section style="margin-top: 15px;"><span style="text-align: left;">2）在</span><strong style="text-align: left;white-space: normal;">身份支柱</strong><span style="text-align: left;">方面，<span style="text-align: left;">正式版中</span>增加了<strong>用户授权</strong>要求。指出目前联邦政府中的许多授权模型都侧重于<strong>RBAC</strong>（<span style="text-align: left;">基于角色的访问控制</span>），应该采取<span style="text-align: left;">RBAC</span>与</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>ABAC</strong></span><span style="text-align: left;">（基于属性的访问控制）<strong>相结合</strong>的方式。</span></section><section style="margin-top: 15px;"><span style="text-align: left;">3）在<strong>网络支柱</strong>方面，<span style="text-align: left;">正式版中</span>增加了关于<strong>网络可见性和攻击面</strong>的讨论。强调了</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>权衡</strong><strong>网络流量监控深</strong></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>度</strong></span><span style="text-align: left;">的观点：即随着零信任的普遍实施，大量流量将被加密。那么，对加密流量执行解密和检查，应该被限制在最低限度。而深度流量检查更适合保护敏感数据并具有少量预期网络客户端的应用程序环境。</span></section><section style="margin-top: 15px;"><span style="text-align: left;">4）在</span><strong><span style="text-align: left;color: rgb(0, 0, 0);">应用和</span></strong><span style="text-align: left;color: rgb(0, 0, 0);"><strong>工作负载<strong style="text-align: left;white-space: normal;">支柱</strong></strong>方面，<span style="text-align: left;">正式版中增加了</span></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>不可变工作负</strong><strong>载</strong></span><span style="text-align: left;color: rgb(0, 0, 0);">的内容。强调基于云的自动化、不可变部署方式，由于具有天然的最小权限特性，可以很好地支持零信任目标。所以，机构在部署服务时，应努力采用不可变的工作负载。</span></section><section style="margin-top: 15px;"><span style="text-align: left;color: rgb(0, 0, 0);">5）<span style="color: rgb(0, 0, 0);text-align: left;">正式版中</span><span style="color: rgb(0, 0, 0);text-align: left;">增加</span>了<strong>任务矩阵</strong>（Task Matrix）。在下面进一步描述。</span></section><section style="text-align: left;margin-top: 15px;"><br/></section><p><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">任务矩阵</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;white-space: normal;margin-bottom: 15px;">正式版附录B中的任务矩阵如下：</section><table cellspacing="0" cellpadding="0" width="538"><tbody><tr style="height:74px;"><td width="65" style="border-width: 1px;border-style: solid;border-color: black;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:center;text-indent:0;line-height:106%;"><strong><span style="font-family:宋体;">部分</span></strong></p></td><td width="331" style="border-top: 1px solid black;border-right: 1px solid black;border-bottom: 1px solid black;border-left: none;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:center;text-indent:0;line-height:106%;"><strong><span style="font-family:宋体;">任务</span></strong></p></td><td width="142" style="border-top: 1px solid black;border-right: 1px solid black;border-bottom: 1px solid black;border-left: none;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:center;text-indent:0;line-height:106%;"><strong><span style="font-family:宋体;">机构行动时间表（最后期限自本备忘录发布日期起）</span></strong></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><strong><span style="font-family: 宋体;color: rgb(0, 0, 0);">全体</span></strong><span style="font-family: 宋体;color: rgb(0, 0, 0);"></span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须向</span>OMB<span style="font-family:宋体;">和</span>CISA<span style="font-family:宋体;">提交一份</span><strong>22-24<span style="font-family:宋体;">财年的实施计划</span></strong><span style="font-family:宋体;">，供</span>OMB<span style="font-family:宋体;">批准，并提交一份</span><strong>23-24<span style="font-family:宋体;">财年的预算估算</span></strong><span style="font-family:宋体;">。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;">60<span style="font-family:宋体;">天内。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">身份</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须为机构用户使用<strong>集中的身份管理系统</strong>，这些系统可以集成到应用程序和通用平台中。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:37px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">身份</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须要求其用户使用<strong>防网络钓鱼</strong>方法，来访问机构托管的帐户。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">身份</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="margin-right:3px;margin-bottom:  0;text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">支持</span>MFA<span style="font-family:宋体;">的面向公众的机构系统，必须允许用户选择使用<strong>防钓鱼认证</strong>。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">一年之内。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">身份</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须从所有系统中</span><span style="font-family: 宋体;color: rgb(172, 57, 255);"><strong>删除</strong></span><span style="font-family:宋体;">要求特殊字符和定期口令轮换的<strong>口令策略</strong>。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">一年之内。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">身份</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构<strong>授权系统</strong>应将至少一个<strong>设备级信号</strong>与认证用户的<strong>身份信息</strong>结合起来。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">设备</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须建立持续、可靠和完整的<strong>资产清单</strong>，包括利用</span>CDM<span style="font-family:宋体;">项目。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">设备</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="margin-right:2px;margin-bottom:  0;text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须确保其</span><strong>EDR<span style="font-family:宋体;">工具</span></strong><span style="font-family:宋体;">符合</span>CISA<span style="font-family:宋体;">的技术要求，并在其机构内部署和运行。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">见</span>M-22-01<span style="font-family:宋体;">。</span></p></td></tr><tr style="height:74px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">设备</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:98%;"><span style="font-family:宋体;">各机构必须与</span>CISA<span style="font-family:宋体;">合作，以识别差距，协调部署，并与</span>CISA<span style="font-family:宋体;">建立<strong>信息共享</strong>能力，如</span>M-22-01<span style="font-family:  宋体;">中所述。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">见</span>M-22-01<span style="font-family:宋体;">。</span></p></td></tr><tr style="height:37px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">网络</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">在技术支持的任何地方，机构都必须使用</span><strong><span style="font-family:宋体;">加密的</span>DNS</strong><span style="font-family:宋体;">，解析</span>DNS<span style="font-family:宋体;">查询。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="37"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">网络</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须对所有生产</span>HTTP<span style="font-family:宋体;">流量，强制执行经过身份验证的</span><strong>HTTPS</strong><span style="font-family:宋体;">，包括不穿越公共互联网的流量。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">网络</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须与</span>CISA<span style="font-family:宋体;">的</span>DotGov<span style="font-family:宋体;">项目合作，在</span>web<span style="font-family:宋体;">浏览器中以仅</span>HTTPS<span style="font-family:宋体;">的形式“预加载”机构所有的</span>.gov<span style="font-family:宋体;">域名。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:93px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="93"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">网络</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="93"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须与</span>CISA<span style="font-family:宋体;">协商，制定<strong>零信任架构计划</strong>，描述机构计划如何<strong>隔离其应用程序和环境</strong>，并将其纳入本备忘录要求的全面实施和投资计划。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="93"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">应用程序和工作负载</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构<strong>系统</strong><strong>授权过程</strong>必须采用自动分析工具和手动专家分析。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">应用程序和工作负载</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须欢迎其互联网接入系统的<strong>外部漏洞报告</strong>。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;">2022<span style="font-family:宋体;">年</span>9<span style="font-family:宋体;">月，与</span>OMB  M-20-32<span style="font-family:  宋体;">和</span>BOD 20-01<span style="font-family:宋体;">保持一致。</span></p></td></tr><tr style="height:74px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">应用程序和工作负载</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构必须选择至少一个需要认证且目前无法通过互联网访问的</span><strong>FISMA<span style="font-family:宋体;">中级系统</span></strong><span style="font-family:宋体;">，并安全地允许其在互联网上进行全功能运行。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="74"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">一年之内。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">应用程序和工作负载</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">各机构必须开始向</span>CISA<span style="font-family:宋体;">和</span>GSA<span style="font-family:宋体;">提供其互联网可访问信息系统使用的任何</span>.gov<span style="font-family:宋体;">主机名。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;">60<span style="font-family:宋体;">天内。</span></p></td></tr><tr style="height:56px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">应用程序和工作负载</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构在部署服务时，尤其是在基于云的基础设施中，应该努力使用<strong>不可变工作负载</strong>。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="56"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">纳入机构实施计划。</span></p></td></tr><tr style="height:2px;"><td width="65" style="border-right: 1px solid black;border-bottom: 1px solid black;border-left: 1px solid black;border-top: none;padding: 0.1px 4px 0px 7px;" height="2"><p style="text-align:center;text-indent:0;line-height:106%;"><span style="font-family:宋体;">数据</span></p></td><td width="331" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="2"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;"><span style="font-family:宋体;">机构<strong>首席数据官</strong>必须与关键机构利益干系人合作，为其企业内的敏感电子文档制定一套初始<strong>分级分类</strong>，目的是自动监控并可以限制这些文档的共享方式。</span></p></td><td width="142" style="border-top: none;border-left: none;border-bottom: 1px solid black;border-right: 1px solid black;padding: 0.1px 4px 0px 7px;" height="2"><p style="text-align:justify;text-justify:inter-ideograph;text-indent:0;line-height:106%;">120<span style="font-family:宋体;">天内。</span></p></td></tr></tbody></table><section style="white-space: normal;margin-top: 15px;">该矩阵的重要性在于，它<strong>高度浓缩</strong>了美国联邦政府对零信任的5个支柱（身份、设备、网络、应用和负载、数据）的<strong>具体要求</strong>，同时做出了明确的<strong>时间进度安排</strong>，具有实实在在的推动力。</section><section style="white-space: normal;margin-top: 15px;">其中，最重要的一条是：各机构必须在<strong>60天内</strong>，提交一份22-24财年的<strong>零信任实施计划</strong>和一份23-24财年的<strong>零信任预算估算</strong>。<br/></section><section style="white-space: normal;margin-top: 15px;">另外，在<strong>身份</strong>方面，比较有趣的一点是：<strong>口令策略不得要求使用特殊字符或定期轮换</strong>。</section><p style="margin-top: 15px;white-space: normal;">之所以会提出这个要求，是因为美国研究人员在关于密码过期策略影响的定量研究论文中，发现<strong style="white-space: normal;">定期轮换</strong><strong>口令</strong>极度影响用户体验，但又不能切实提高口令安全性。</p><p style="margin-top: 15px;white-space: normal;">作为每隔几个月就被逼迫修改系统登录口令的切实感受者，笔者深深地赞同这一点。</p><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span><span style="text-align: center;"></span></section><section style="margin-top: 15px;"><span style="text-align: center;"></span></section>



<p><a href="2247494558">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=97c23a66&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494558%26idx%3D1%26sn%3D24dbd295328876902a064e57eda63b7c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 28 Jan 2022 06:08:00 +0800</pubDate>
    </item>
    <item>
      <title>CrowdStrike：零摩擦，零信任</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494539&amp;idx=1&amp;sn=031876c75be5408b3212290b21b14b42</link>
      <description>我为何与众不同</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2021-12-31 00:06</span> <span style="display: inline-block;"></span>
</p>

<p>我为何与众不同</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=24841250&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNz5tBHAE0NaiaD4MWxmbSUsELgVVZDOurrqlnvYggCOibHoVqSu0KqtpH59tuLFdKZVRUpcSLUpL9g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<strong>4</strong><span style="color: rgb(0, 0, 0);"><strong>800</strong></span>字  <span style="color:#000000;"><strong>9</strong></span>图表  阅读约<span style="color:#000000;"><strong>10</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;"><span style="text-align: center;">CrowdStrike已经在向零信任快速挺进。</span></p><p style="margin-top: 10px;white-space: normal;text-align: left;"><span style="text-align: center;">CrowdStrike占据<strong>全球</strong><strong>网络安全公司市值排行榜的首位</strong>，已经有相当长一段时间了。作为一家以<strong>终端安全</strong>打天下、以<strong>安全云服务</strong>立天下、<strong>上市</strong></span><span style="text-align: center;color: rgb(0, 0, 0);"><strong>一年半</strong></span><span style="text-align: center;"><strong>即市值第一</strong>的安全公司，其传奇发展令人着迷。</span></p><p style="margin-top: 10px;white-space: normal;text-align: left;"><span style="text-align: center;"><span style="text-align: center;">CrowdStrike的特点是</span><strong style="white-space: normal;text-align: center;">永远在创新</strong><span style="text-align: center;">。而本文要谈的即是<span style="text-align: center;">它在零信任领域的思路和布局。</span></span></span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: center;">如果广泛阅读国外的零信任宣传资料，会经常看到&#34;<strong style="text-align: center;white-space: normal;">摩擦</strong>&#34;(Friction)这个词。意思是指：<strong>零信任通常会让用户感到不舒服</strong>。至少有两方面原因：一是<strong style="white-space: normal;text-align: center;">零信任的使用</strong><span style="text-align: center;">会体验不佳、令人不爽</span></span><span style="text-align: center;">；二是<strong style="white-space: normal;text-align: center;">零信任的落地</strong><span style="text-align: center;">会阻碍重重、倍感挫折</span></span><span style="text-align: center;">。</span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: center;">所以，<span style="text-align: center;">CrowdStrike</span>的目标是努力构建一个<strong>零摩擦（无摩擦）的零信任</strong>。</span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: center;">在本文的最后一节（</span><strong style="text-align: center;">为何与众不同</strong><span style="text-align: center;">）中，笔者梳理总结了CrowdStrike近年来的<strong>主要发力点</strong>，包括<strong>零信任</strong>、<strong>数据安全</strong>、<strong>XDR</strong>、<strong>新一代</strong><strong>日志管理</strong>。再一次为其<strong>颠覆式创新</strong>能力所折服。</span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: center;">对于想模仿</span>CrowdStrike的<span style="text-align: center;">公司，需要回答一个问题：是否具有</span>类似CrowdStrike<span style="text-align: center;">的基因，包括<strong>端点基因、颠覆基因、创新基因</strong>。因为基因难以被模仿。</span></p></section></section></section></section></section><p style="margin-top: 15px;text-align: center;"><strong style="font-size: 20px;text-align: center;">目  录</strong></p><section>1.向零信任进军</section><section>2.零信任的支柱<br/></section><p>3.以三段论实现零信任支柱</p><p>4.零摩擦的零信任方法</p><p>5.零信任的下一步：数据安全</p><p>6.<strong>为何与众不同</strong><br/></p><section style="text-indent: 2em;">1）CrowdStrike产品能力图变迁</section><section style="text-indent: 2em;">2）CrowdStrike主要收购活动</section><section style="text-indent: 2em;">3）CrowdStrike发展思路<strong>洞察</strong></section><p><br/></p><p><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">向零信任进军</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;">在Crowdstrike看来，无论企业的动机是<strong>业务转型</strong>还是<strong>降低风险</strong>，<strong>零信任策略</strong>都是实现企业目标的最佳和最安全的途径，而<strong>保护身份存储</strong>则是零信任策略的关键。<br/></section><section style="margin-top: 15px;">2020年9月，Crowdstrike收购<strong>Preempt </strong>Security，后者是零信任访问技术的提供商。Crowdstike 为该公司支付了<span style="color: rgb(172, 57, 255);"><strong>9600万美元</strong></span>。CrowdStrike首席执行官George Kurtz 解释说，“在完成了第二轮<strong>‘</strong><span style="color: rgb(172, 57, 255);"><strong>百天百个</strong></span><strong>’客户之旅</strong>（我在100天内会见了100名客户和潜在客户）后，我明确地听到，企业正在寻找一种现代化的以身份和工作负载为中心的<strong>零信任安全战略</strong>，以奠定他们的<strong>安全转型</strong>基础。” </section><section style="margin-top: 15px;white-space: normal;">与Preempt的产品融合之后，Crowdstrike推出了新的<strong>身份保护平台——</strong><strong style="text-align: center;">Falcon Identity Protection</strong>（猎鹰身份保护），用于<span style="text-align: center;">保护员工身份，<span style="text-align: center;">可以帮助企业实现</span><strong style="text-align: center;white-space: normal;">零摩擦</strong><span style="text-align: center;">的</span><strong style="text-align: center;white-space: normal;">零信任</strong><span style="text-align: center;">。</span></span></section><section style="margin-top: 15px;"><span style="text-align: center;">由于<strong>80%的成功入侵都涉及</strong></span><span style="text-align: center;color: rgb(172, 57, 255);"><strong>失陷凭据</strong></span><span style="text-align: center;">，Falcon Identity Protection将身份威胁检测和对本地和云身份的条件访问统一起来。通过使用身份、行为、风险分析，得以跟威胁抢占先机，从而保护<strong>400多家企业</strong>的<strong>400多万个身份</strong>。</span></section><section style="white-space: normal;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">零信任的支柱</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="margin-top: 15px;">采用零信任策略来确保员工身份安全的组织，应通过<strong>六个支柱</strong>（身份（用户）、端点（设备）、网络、应用程序/工作负载、自动化、分析）来实现统一的可见性、检测、执行。</p><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/4EtGnz3lAPN6hLqcfDd7z8eNUEvO8DfFib5azkkza0fwlZuXFGmrX9XtXthjy0BmSEQ2BAOcMRpl2UZ7wLMyw6Q/640?wx_fmt=png" data-cropx1="5.008650519031141" data-cropx2="567.9809688581314" data-cropy1="0" data-cropy2="510.8823529411765" data-ratio="0.9074733096085409" data-s="300,640" style="text-align: center;width: 562px;height: 510px;" data-type="jpeg" data-w="562" src="https://wechat2rss.xlab.app/img-proxy/?k=4dfaf4aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPNlzjr2c5oHb7r93NugQF9ialQvua28kCSeYYPvlKibictpKst1K5Wy93fvL47f6Uz0XSf8DTMV65kicA%2F640%3Fwx_fmt%3Djpeg"/><br/></section><section style="text-align: center;margin-top: 15px;">图1-<span style="text-align: center;">CrowdStrike</span>零信任安全模型的六大支柱<br/></section><section style="margin-top: 15px;">关于零信任的支柱，之前已经介绍过多次，不再赘述。这里仅解释下<span style="text-align: center;">CrowdStrike</span><strong>六大支柱</strong><span style="text-align: center;">与下面的<strong><span style="text-align: center;">Forrester零信任</span></strong><strong style="text-align: center;white-space: normal;">七大支柱</strong>（下图）的区别：</span></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="margin-top: 5px;"><span style="text-align: center;">Forrester将<strong>数据</strong>作为零信任的一大支柱；</span></p></li><li><p style="margin-top: 5px;"><span style="text-align: center;">CrowdStrike将<strong><span style="text-align: center;">数据</span></strong><span style="text-align: center;">和</span><strong><span style="text-align: center;">身份</span></strong>作为基础支撑层，<span style="text-align: center;">分别体现零信任是<strong>以数据为中心</strong>和<strong>以身份为中心</strong>的安全模型。</span></span></p></li></ul><section style="margin-top: 15px;text-align: left;"><strong><span style="text-align: center;">以笔者的观点看</span></strong><span style="text-align: center;">：之所以CrowdStrike将</span><strong style="text-align: center;white-space: normal;">身份</strong><span style="text-align: center;">作为零信任的基础支撑层，意味着CrowdStrike在零信任领域的</span><strong style="text-align: center;white-space: normal;">技术路线</strong><span style="text-align: center;">是</span><span style="color: rgb(172, 57, 255);"><strong style="text-align: center;white-space: normal;">IAM</strong></span>；之所以<span style="text-align: center;">CrowdStrike没有把<strong>数据</strong>作为一大支柱，则可能是由于其还未涉足<strong>数据安全</strong>领域。</span></section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.689795918367347" style="text-align: center;" data-type="jpeg" data-w="490" src="https://wechat2rss.xlab.app/img-proxy/?k=ab307381&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FpLEuriaaPnU3dbGnZXHs2tNHKOQADbPCxJlzLMqNZOByDFhKzjLECicjib4FvSuDLTqmiaib4agMjluDZgH3oLic8f3Q%2F640%3Fwx_fmt%3Djpeg"/></section><section style="margin-top: 15px;text-align: center;"><span style="text-align: center;">图2-Forrester零信任扩展生态系统的七大支柱</span></section><section style="margin-top: 15px;text-align: left;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">以三段论实现零信任支柱</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;">为了创建一个完整零信任安全栈，需要实现上面提到的零信任6大支柱，这显然既昂贵又复杂。市面上已经有针对其中一/两个支柱的<span style="color: rgb(172, 57, 255);"><strong>单点化</strong></span><strong>解决方案</strong>，但是在实施时，不同的方案可能不会很好地集成在一起。</section><section style="margin-top: 15px;">Falcon Identity Protection提供了一个<span style="color: rgb(172, 57, 255);"><strong>集中</strong><strong>化</strong></span><strong>解决方案</strong>，该解决方案通过<strong>动态身份风险评估</strong>来控制身份访问，以防止穿越网络的横向移动。同时，它提供了一种<strong>灵活</strong>的认证方法，为最终用户带来<span style="color: rgb(172, 57, 255);"><strong>零摩擦</strong></span>的使用体验。</section><section style="margin-top: 15px;"><img class="rich_pages wxw-img" data-ratio="1.0008896797153024" style="text-align: center;" data-type="png" data-w="1124" src="https://wechat2rss.xlab.app/img-proxy/?k=2d2616bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPO2dYjMVdZVoibPtmMsrKI67eRVR0JSNc8PlVFc9JiaybzvOiaFenHYA8CEEp9ibjRVO3H9ajfWc2TREA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;text-align: center;">图3-CrowdStrike零信任三段论</section><section style="margin-top: 15px;white-space: normal;">如上图所示，通过&#34;<strong>分段-自动化-验证</strong>&#34;（图中内环）三段论，实现了<strong>零信任六大支柱</strong>（图中外环）。</section><section style="margin-top: 15px;"><strong>1）分段（Segment）</strong><br/></section><section style="margin-top: 15px;">在零信任模型中，<strong>分段是降低风险的关键因素</strong>。通过<span style="color: rgb(172, 57, 255);"><strong>身份分段</strong></span>，可以抑制大部分入侵的横向移动。企业需要将<strong>用户帐户</strong>（员工、承包商、远程工作人员，甚至特权用户）和<strong>端点</strong>都分段为<span style="color: rgb(172, 57, 255);"><strong>微分段</strong></span>。</section><section style="margin-top: 15px;"><span style="color: rgb(0, 0, 0);"><strong>所有数据源和计算服务都被视为资源</strong>：笔记本电脑、台式机、物理服务器、虚拟机等实体，都被视为资源。所有这些<strong>端点</strong>都与<strong>用户（人员账户或服务<strong style="white-space: normal;">账户</strong>）相关联</strong>。</span></section><section style="margin-top: 15px;"><strong>2）自动化（Automate）</strong><br/></section><section style="margin-top: 15px;">零信任不能依靠人工方式，来审核用户行为模式并判断他们是否可疑。<strong>安全需要自动化和智能化</strong>，以在每个事务上尽可能多地接收数据，从而发现模式、意图、异常、事件。</section><section style="margin-top: 15px;">零信任方案通过专有的人工智能和机器学习（<strong>AI/ML</strong>）能力，来评估用户的信任等级。也可以从<strong>人类分析师</strong>的调查诊断中进行学习。</section><section style="margin-top: 15px;"><strong>对资源的访问由动态策略决定。</strong>动态策略包括客户端身份、应用程序、请求资产的可观察状态，也可以包括其他<strong>行为属性</strong>，如<span style="color: rgb(172, 57, 255);"><strong>100多种行为模式</strong></span>。</section><section style="margin-top: 15px;"><strong>3）验证（Verify）</strong></section><section style="margin-top: 15px;">验证模型包括针对模式和已知行动的验证，以及针对凭证健康和行为分析的验证。零信任意味着<strong>动态验证</strong>和<strong>建立常态</strong>，从而使<strong>异常</strong>更迅速地显现出来。</section><section style="margin-top: 15px;"><strong>为了确保</strong><span style="color: rgb(172, 57, 255);"><strong>无摩擦</strong></span><strong style="white-space: normal;">的用户体验</strong>，<strong>仅在风险增加时才触发MFA</strong>。绝不会<strong>为具有</strong><span style="color: rgb(0, 0, 0);"><strong>相同源和目标</strong></span><strong>的常规任务添加持续的重新认证而降低业务速度</strong>。</section><section style="margin-top: 15px;">零信任系统提供了一个<span style="color: rgb(172, 57, 255);"><strong>90天窗口基线</strong></span>，在该时间窗口中，系统将<strong>持续学习和调整基线</strong>，以改进认证策略、策略创<span style="color: rgb(0, 0, 0);">建和执行</span>。</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">零摩擦的零信任方法</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;">零信任的成功，可以通过三种方式来衡量：</section><ul class="list-paddingleft-2" style="width: 577.417px;"><li><section style="margin-top: 5px;"><strong>员工体验：</strong>跨组织中的所有通道和触点，提供一致或更优的用户体验；</section></li><li><section style="margin-top: 5px;"><strong>运营效率：</strong>在时间、人力资源、资金方面，简化运营、降低风险、降低开销的推<span style="color: rgb(0, 0, 0);">动力</span>；</section></li><li><section style="margin-top: 5px;"><strong>风险降低：</strong>持续跟踪并获得<strong>风险评分</strong>的改善。通过降低风险，帮助企业回归核心业务。</section></li></ul><section style="margin-top: 15px;">CrowdStrike的零摩擦零信任方法，正是为了帮助客户取得零信任的成功。<br style="white-space: normal;"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.5065" data-w="2000" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=6dc809f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPO2dYjMVdZVoibPtmMsrKI67CpXmuz8vD7X86sp8j9uLDG7ayyibQ0FP4gicWh9Hs01AXIaavRLiaZXJA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图4-<span style="text-align: justify;">CrowdStrike</span>零信任部署模型</section><section style="margin-top: 15px;"><strong>1）基于风险的条件访问</strong>（上图中蓝色能力模块）<br/></section><section style="margin-top: 15px;"><strong>风险是一个不断变化的分值</strong>。当用户加入或者改变角色和团队时，他们的行为和访问需求就会发生变化。零信任系统对用户及其行为以及会话和端点的质量进行<strong>用户建模</strong>，从多个来源提取多种数据，为组织中的每个用户创建<strong>风险评分</strong>。</section><section style="margin-top: 15px;"><strong style="white-space: normal;">在一天或一个会话中多次进行登录/认证挑战，必然会影响用户体验</strong>。为了提供<span style="color: rgb(172, 57, 255);"><strong>零摩擦</strong></span>的用户体验，零信任系统收集<strong>用户模式</strong>数据，并通过行为变化或异常检测来评估实际风险。零信任系统收集每个请求的<strong>上下文</strong>，以将该活动与该用户/组的活动基线进行比较。</section><section style="margin-top: 15px;">基于风险的条件访问，可以检测和阻止<strong style="white-space: normal;">沿着MITRE ATT&amp;CK杀伤链的凭据和身份存储上的复杂威胁</strong>，<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">例如权限提升（</span><span style="color: rgb(0, 0, 0);font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">凭证喷洒、暴力破解、泄露口令</span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">）、横向移动（PowerShell、传递散列（PtH）、Golden Ticket、RDP）</span>、NTLM中继攻击等。</section><section style="margin-top: 15px;">当存在可疑或恶意活动时，零信任系统将<span style="color: rgb(0, 0, 0);">hold住</span>访问请求。基于自适应策略，可以在任何网络资源（包括PowerShell、RDP、文件夹等）上，使用MFA、电子邮件、短信、阻止或警报的各种<strong style="white-space: normal;">实时机制</strong>，来质询用户。</section><section style="margin-top: 15px;"><strong>2）<strong style="white-space: normal;">零信任检测引擎</strong></strong><br/></section><section style="margin-top: 15px;white-space: normal;"><strong><strong style="white-space: normal;">Falcon零信任</strong>检测引擎</strong>既包括<strong>静态规则</strong>（基于已知的攻击模式和特征码），也包括<strong>异常检测算法</strong>（可检测复杂的攻击）。综合多种检测模型，就可以检测出各种类型的恶意活动，如特权提升、横向移动、地理异常等。</section><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.6232044198895028" data-w="905" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e240e097&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNlzjr2c5oHb7r93NugQF9iaOHGVVqbVsyE8aTrIyeJwSrJUSWW6jEBCqiaRzCbKibTa6nZ6ibcnPhDfA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;text-align: center;">图5-零信任检测引擎的规则配置<strong style="white-space: normal;"></strong><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>3）零信任的<strong>实施</strong></strong></section><section style="margin-top: 15px;"><strong><strong style="white-space: normal;"></strong></strong><strong>实施速度快</strong>。零信任系统可以很快建立起来，<strong style="white-space: normal;"><strong><strong>管理</strong>的部署和数据的收集工作，可在</strong></strong><span style="color: rgb(172, 57, 255);"><strong style="white-space: normal;"><strong>半天</strong></strong></span><strong style="white-space: normal;"><strong>内完成</strong>。</strong>而<strong>价值实现的时间，取决于进行</strong><span style="color: rgb(172, 57, 255);"><strong>身份存储普查</strong></span><strong>的时间</strong>，包括普查用户、特权用户、影子用户、服务帐户，以及它们各自的弱点或不足。</section><section style="margin-top: 15px;"><strong>认证集成广。</strong>零信任系统与几乎所有主流<strong>MFA</strong>供应商合作（<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">包括但不限于Duo、Azure MFA、RSA SecurID、CA、Symantec、Okta等</span>），扩展到云端和本地资源，甚至是遗留系统，而不会造成用户的口令疲劳。通过<strong>为所有SSO供应商提供插件</strong>，该解决方案允许客户选择认证，为SSO活动提供完全可见性、风险和威胁检测，而<strong>不需要端点代理</strong>。<br/></section><section style="margin-top: 15px;"><strong>安全集成广</strong>。零信任系统可与现有的安全方案集成，以增加风险评分和实时信息，使得整体安全方案更加智能。零信任系统还为一些主要的<strong>SOAR</strong>（安全协调、自动化和响应）供应商和<strong>SIEM</strong>系统提供了插件——提供有关任何IP和设备、与之相关的用户帐户以及已知威胁的详细上下文信息。对于经验丰富的SIEM或SOC分析师，零信任系统提供CEF和LEEF格式的API，来帮助构建感兴趣的规则和事件。<br/></section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">零信任的下一步：数据安全</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><h1 style="margin-top: 15px;white-space: normal;"><span style="font-size: 17px;">值得注意的是，CrowdStrike似乎没有谈及<strong>数据安全</strong>。因此，虽然CrowdStrike已经吸收了<strong>主体侧身份零信任</strong>的概念，但还没有涉及到<strong>客体侧数据零信任</strong>的领域。如果你问两者有何不同，请参见<span style="color: rgb(0, 82, 255);">《</span><span style="color: rgb(0, 82, 255);text-decoration: underline;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494522&amp;idx=1&amp;sn=863d352d7c890967f4333820f0adaa25&amp;chksm=97fa361ca08dbf0a47e0acecd04a959e108aaa4930cafe6b0af40a882f36ddb7b0f4c7dc7dcb&amp;scene=21#wechat_redirect" textvalue="数据安全保护和治理的新方法" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">数据安全保护和治理的新方法</a></span><span style="color: rgb(0, 82, 255);">》</span>。既然身份侧的零信任会有如此多的摩擦，那么数据侧的零信任毫无疑问会有更多的摩擦。</span></h1><section style="margin-top: 15px;white-space: normal;">正当笔者<strong>自以为是</strong>地认为发现了CrowdStrike<strong>产品布局缺项</strong>的时候，好在谨慎地浏览了一遍CrowdStrike的Blog（博客），竟然发现：他刚刚进行了数据安全的布局！在<strong>2021年11月</strong>1日对外官宣，收购<strong>SecureCircle</strong>公司，以进军<strong>端点数据安全</strong>领域。</section><section style="margin-top: 15px;white-space: normal;">CrowdStrike认为：<strong>多年来数据保护市场几乎没有创新，而<strong style="white-space: normal;">DLP</strong>(<strong style="white-space: normal;">数据防泄漏</strong>)已经被证明是失败的技术</strong>。DLP解决方案的不足在于，它们<strong>仅在数据离开端点时</strong>并且仅在由一组复杂的<strong>预配置规则和行为参数</strong>触发时，才会阻止或加密数据。而攻击者很清楚 DLP 的弱点，并不断改进他们的技巧，以构建特定的恶意软件和勒索软件。DLP已经无效！我们需要一种<strong>新模型</strong>来实现<strong>无摩擦的数据保护</strong>。</section><section style="margin-top: 15px;white-space: normal;">在吸收SecureCircle的技术之后，CrowdStrike 将可实现<strong>数据保护的现代化</strong>，将<strong>零摩擦的零信任</strong>，扩展为<span style="color: rgb(172, 57, 255);"><strong>零摩擦的数据安</strong><strong>全</strong></span>。从而使其客户能够<span style="color: rgb(0, 0, 0);">同时</span>在<strong>设备级别、身份级别、</strong><span style="color: rgb(0, 0, 0);"><strong>数据级别的不同级别</strong>，实现</span>零信任。而所有这一切，都是通过端点上的 CrowdStrike <span style="color: rgb(172, 57, 255);"><strong>轻量级代</strong><strong>理</strong></span>提供！这也再一次表明，<span style="color: rgb(172, 57, 255);"><strong>端点就是一切</strong></span>！<br/></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">为何与众不同</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;"><br/></p><section style="margin-top: 15px;white-space: normal;"><strong><span style="text-align: center;">1）<span style="text-align: center;">CrowdStrike产品能力图变迁</span></span></strong></section><section style="margin-top: 15px;white-space: normal;"><span style="text-align: center;">笔者积攒了<span style="text-align: center;">CrowdStrike近两年来的产品能力图，以观察其发展思路：</span><br/></span></section><section style="white-space: normal;text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-ratio="0.4099173553719008" data-s="300,640" data-w="605" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=48c61c36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNz5tBHAE0NaiaD4MWxmbSUslekic7icFR86hWlWNjEdBnWeXpnZVGKrap41wA5GuatPLUOtThwwzb9g%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图6-CrowdStrike Falcon端点保护平台（<span style="color: rgb(0, 0, 0);">2020版</span>）</section><section style="margin-top: 15px;white-space: normal;text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.5883597883597883" style="text-align: center;" data-type="png" data-w="945" src="https://wechat2rss.xlab.app/img-proxy/?k=0a37a97b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNlzjr2c5oHb7r93NugQF9ia2Yg5HREMk0HUhibSrKzKDVe3kI2xB2yZlO51xhf1Ep1wk6pjLITcCYA%2F640%3Fwx_fmt%3Dpng"/><br/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><span style="text-align: center;">图7-CrowdStrike产品能力（2021年4月版）</span></section><section style="margin-top: 15px;white-space: normal;text-align: left;">注：此图中，以绿色标记了相对于2020版的重大变化：增加了<strong>云安全</strong>领域和<strong>身份保护（<strong style="white-space: normal;text-align: center;">零信任</strong>）</strong>领域。<br/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.703125" data-w="1600" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=c81b7a14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPNlzjr2c5oHb7r93NugQF9iaSc97GDPvjngks2rwLcoXgzaroEgIkJxqZibq7RWkiczHwRRlMEYElktw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><span style="text-align: center;">图8-CrowdStrike产品能力（2021年12月版）</span></section><section style="margin-top: 15px;">注：<span style="text-align: left;">此图中，以黄色圆圈标记了相对于2021年4月版的主要变化：增加了</span>端点安全中的<strong>XDR</strong>；增加了<strong>HUMIO</strong>（日志管理）+HUMIO数据库；增加了<strong>FUSION</strong>（自动化编排）。</section><p style="white-space: normal;margin-top: 15px;"><strong><span style="text-align: center;">2）CrowdStrike主要收购活动</span></strong></p><section style="margin-top: 15px;">接下来，按图索骥，查阅Crowdstrike官网新闻，梳理Crowdstrike自2019年上市以来的相关事件：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><section style="margin-top: 5px;">2019年6月，Crowdstrike上市；</section></li><li><section style="margin-top: 5px;">2020年9月，CrowdStrike宣布收购<strong>Preempt </strong>Security，增强<strong>零信任</strong>安全能力；</section></li><li><section style="margin-top: 5px;">2021年2月，CrowdStrike 宣布收购 <strong>Humio</strong>，为下一代无索引 XDR 提供业界最先进的数据平台；<br/></section></li><li><section style="margin-top: 5px;">2021年10月，CrowdStrike宣布推出首创的 <strong>XDR </strong>模块，以在整个安全栈中提供<strong>实时检测和自动响应</strong>；</section></li><li><section style="margin-top: 5px;">2021年10月，CrowdStrike宣布推出 <strong>Fusion</strong>自动化工作流解决方案，以实现<strong>SOAR </strong>(安全编排、自动化和响应) 框架；<br/></section></li><li><section style="margin-top: 5px;">2021年11月，CrowdStrike 宣布收购 <strong>SecureCircle</strong>，以实施<strong>零信任数据保护</strong>。</section></li></ul><p style="white-space: normal;margin-top: 15px;"><strong><span style="text-align: center;">3）CrowdStrike发展思路洞察</span></strong></p><section style="margin-top: 15px;">综合上述信息，笔者从中得出了两方面结论：</section><h1 style="margin-top: 15px;"><strong><span style="font-size: 17px;">关于零信任</span></strong><span style="font-size: 17px;">，CrowdStrike的发展思路是：</span></h1><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><h1 style="margin-top: 5px;">与<strong>零信任厂商</strong>（Zscaler、Illumio、Okta等）合作，推出联合零信任方案；<br/></h1></li><li><h1 style="white-space: normal;margin-top: 5px;"><span style="font-size: 17px;">通过收购<strong>Preempt</strong>，弥补</span><strong style="font-size: 17px;">零信任身份安全</strong><span style="font-size: 17px;">；</span><br/></h1></li><li><h1 style="margin-top: 5px;"><span style="font-size: 17px;">通过收购<strong>SecureCircle</strong>，弥补<strong>零信任数据安全</strong>；</span></h1></li><li><h1 style="margin-top: 5px;"><span style="font-size: 17px;">通过这两个收购，完成了对零信任领域的整体布局。</span></h1></li></ol><section style="margin-top: 15px;"><span style="font-size: 17px;"><strong>关于XDR</strong>，CrowdStrike的发展思路是：</span></section><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><section style="margin-top: 5px;"><span style="font-size: 17px;">EPP-&gt;EDR-&gt;XDR；</span></section></li><li><section style="margin-top: 5px;"><span style="font-size: 17px;">创造<strong>威胁图谱</strong>，增强<strong>威胁关联</strong>能力；</span></section></li><li><section style="margin-top: 5px;"><span style="font-size: 17px;">收购</span><span style="font-size: 17px;color: rgb(172, 57, 255);"><strong style="white-space: normal;">Humio</strong></span><span style="font-size: 17px;">，增强<strong>日志管理</strong>能力；</span></section></li><li><section style="margin-top: 5px;"><span style="font-size: 17px;">推出<strong style="white-space: normal;">Fusion</strong>，增加安全<strong>自动化编排</strong>能力。<br/></span></section></li></ol><section style="margin-top: 15px;white-space: normal;text-align: left;">其中，CrowdStrike<strong>威胁图谱</strong>（<span style="color: rgb(0, 0, 0);">Threat Graph</span>）被誉为CrowdStrike的<span style="color: rgb(172, 57, 255);"><strong>云中大脑</strong></span>。它出现在<strong>图6-8</strong>的基础平台层中，之前在<span style="color: rgb(0, 82, 255);">《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493784&amp;idx=1&amp;sn=acef011a6828a3b3be9442c159150395&amp;chksm=97fa35fea08dbce863cb21cfa0db953c84600e373a5bcae24d29979e65f364291d22a1a1c0ef&amp;scene=21#wechat_redirect" textvalue="CrowdStrike | 无文件攻击白皮书" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="text-decoration: underline;">CrowdStrike | 无文件攻击白皮书</span></a>》</span>中简单介绍过，不再赘述。</section><section style="margin-top: 15px;white-space: normal;text-align: left;">最后，隆重介绍一下<strong style="white-space: normal;">日志管理平台</strong><span style="color: rgb(172, 57, 255);"><strong style="white-space: normal;">Humio</strong></span><strong style="white-space: normal;">。</strong>这个平台是在2021年收购的。从图8中可以看出，它的地位与<strong style="text-align: left;white-space: normal;">威胁图谱</strong>并列，所以也是非常重要的基础平台。<span style="text-align: justify;">Humio被誉为</span><span style="color: rgb(172, 57, 255);"><strong style="text-align: justify;">下一代</strong></span><strong style="text-align: justify;">日志管理系统。其颠覆之处在于：</strong></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><section style="margin-top: 5px;"><strong style="text-align: justify;"></strong><span style="text-align: left;color: rgb(172, 57, 255);"><strong style="text-align: justify;">无索引</strong></span><strong style="white-space: normal;">架构</strong>。众所周知，为了<span style="text-align: left;">执行</span>大规模搜索，传统的日志管理系统会在数据被摄取时编制<strong>索引</strong>。而<strong>Humio</strong><strong style="text-align: justify;"><strong>最大的颠覆性就在于：它是一种</strong></strong><span style="color: rgb(0, 0, 0);"><strong style="text-align: justify;"><strong>无索引</strong></strong></span><strong style="text-align: justify;"><strong>的架构！</strong></strong></section></li><li><section style="margin-top: 5px;"><strong style="text-align: justify;"></strong><strong>超强存储能力</strong>。借助 Humio 的高级压缩能力，其存储的数据量是传统基于索引的日志解决方案的 <strong>5-15 倍</strong>（或更多）。</section></li><li><section style="margin-top: 5px;"><span style="color: rgb(172, 57, 255);"><strong>秒级搜索PB级数据</strong></span>。Humio 使用智能过滤和高级压缩来<strong>减少数据集</strong>，然后将所有数据加载到<strong>内存</strong>中，使得<strong>暴力搜索</strong>速度更快，从而<span style="text-align: left;">在</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>一秒内搜索 1 PB 数据</strong></span><span style="text-align: left;"><strong>并获得结果</strong>！</span></section></li><li><section style="margin-top: 5px;"><span style="text-align: left;color: rgb(172, 57, 255);"><strong>记录一切</strong></span><span style="text-align: left;">。<strong style="white-space: normal;">SIEM<span style="text-align: left;">或传统日志管理产品</span></strong>通常只是跟踪<strong style="white-space: normal;">预先选择</strong>的数据（因为其摄取和存储所有日志的成本高得惊人），从而在监控中留下盲点。而一旦有了 Humio，企业不再被迫做出关于记录哪些数据以及保留多长时间的艰难决定。通过<strong>记录所有内容</strong>，Humio 客户可以获得实时检测和响应任何事件所需的<strong>完整可见性</strong>。</span></section></li><li><section style="margin-top: 5px;"><span style="text-align: left;color: rgb(172, 57, 255);"><strong>成就XDR</strong></span><span style="text-align: left;">。Humio 彻底解决了 <strong>XDR </strong>的<strong>大数据挑</strong><strong>战</strong>。如果没有新一代日志管理能力，将无法支撑XDR所需的大数据能力。</span><strong style="text-align: justify;"></strong></section></li></ul><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.6581892166836215" data-w="983" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e4d3dc9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPO2dYjMVdZVoibPtmMsrKI67VICYwgwiaKo0wqnAtw3dyMR1Richia8yGiaccBqTM3GWriaQo9PRURL8r3Q%2F640%3Fwx_fmt%3Dpng"/></section><p style="text-align: center;"><span style="font-size: 17px;">图9-为什么无索引架构可以这么快<br/></span></p><section style="margin-top: 15px;white-space: normal;text-align: left;"><span style="text-align: justify;">CrowdStrike 一直在创造一种</span><strong style="text-align: justify;">创新性</strong><span style="text-align: justify;">的文化。</span><strong style="text-align: justify;">颠覆</strong><span style="text-align: justify;">是这家公司的底线。</span><br/></section><section style="margin-top: 15px;"> </section><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span><span style="text-align: center;"></span></section>



<p><a href="2247494539">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=bfb1d822&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494539%26idx%3D1%26sn%3D031876c75be5408b3212290b21b14b42%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 31 Dec 2021 00:06:00 +0800</pubDate>
    </item>
    <item>
      <title>数据安全保护和治理的新方法</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494522&amp;idx=1&amp;sn=863d352d7c890967f4333820f0adaa25</link>
      <description>零信任是数据访问控制的必杀技</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2021-11-28 14:43</span> <span style="display: inline-block;"></span>
</p>

<p>零信任是数据访问控制的必杀技</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=098d8e9f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPMdQ1ITibpMiaOR1RZ3TyjNTT8fxLDqCM3APyFTrPf5RfBl5ozZqGPmP7P2ic1El5y1kFo7mAALWo6sg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;"><br/></p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;">秉持<strong>数据驱动战略</strong>的<strong>数据驱动型组织</strong>，正在利用数据，以前所未有的速度开创未来。同时，也面临日益增长的安全、隐私、合规风险。</p><p style="text-align: left;margin-top: 10px;">在过去几十年中，保护敏感数据的现有方法是孤立地建立起来的，缺乏整体性。考虑到各组织正在越来越严格的隐私法规下处理比以往任何时候都多的数据，<strong>寻求一种新方法是极为必要的</strong>。</p><p style="text-align: left;margin-top: 10px;">当今，数据访问控制的<strong style="outline: 0px;max-width: 100%;letter-spacing: 2px;white-space: normal;box-sizing: border-box !important;overflow-wrap: break-word !important;">所谓“最佳实践”</strong>，是创建一个明确定义的可访问数据列表，并在此基础上制定权限<span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;">。</span><span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;">然而，不幸的是，一旦考虑到现实世界</span><span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;">的</span><span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;">企业数据挑战，</span><span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;">这根本不可行。</span></p><p style="text-align: left;margin-top: 10px;"><span style="outline: 0px;max-width: 100%;letter-spacing: 2px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="white-space: normal;">一个好的数据保护和数据治理解决方案</strong>，必须能够实现正常的数据访问，而不是中断或产生负面影响。而<strong style="white-space: normal;">一个伟大的解决方案，将使数据访问比以前更容易、更高效、更广泛。</strong></span></p><p style="text-align: left;margin-top: 10px;"><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">数据访问控制</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">是<strong>零信任</strong>的</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">最后环节</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">和</span><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">终极目标</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">。</span><strong>基于零信任的数据访问控制，必将成为数据安全保护和治理的新方法</strong>。</p></section></section></section></section></section><p style="text-align: center;margin-top: 25px;"><strong style="font-size: 20px;">目  录</strong></p><section style="margin-top: 15px;"><strong><span style="text-indent: 34px;text-align: center;">1. 背景：数据驱动战略与DataSecOps</span></strong></section><section style="text-indent: 2em;">1）数据驱动战略与数据驱动型组织</section><section style="text-indent: 2em;">2）数据民主化与DataOps</section><section style="text-indent: 2em;">3）数据安全与DataSecOps</section><p><strong><span style="text-indent: 34px;text-align: center;">2. 数据安全保护为什么这么难</span></strong></p><section style="text-indent: 2em;">1）数据的规模化治理难题</section><section style="text-indent: 2em;">2）为什么数据分级分类很难</section><section style="text-indent: 2em;">3）仅凭日志是远远不够的</section><section style="text-indent: 2em;">4）数据存取方式的演变</section><section style="text-indent: 2em;">5）难以设置的访问权限</section><section style="text-indent: 2em;"><span style="text-indent: 2em;">6）新法规要求组织重新思考其数据战略</span><br/></section><p><strong><span style="text-align: center;text-indent: 34px;">3. 保护敏感数据的现有方法</span></strong></p><section style="text-indent: 2em;">1）数据编目与<span style="text-indent: 34px;">分级</span>分类</section><section style="text-indent: 2em;">2）访问控制和权限管理</section><section style="text-indent: 2em;">3）掩蔽、加密、符号化</section><p><strong><span style="text-indent: 34px;text-align: center;">4. 数据安全保护和治理的新方法</span></strong></p><section style="text-indent: 2em;">1）执行<span style="color: rgb(0, 0, 0);">动态和细粒度数据访问控制</span></section><section style="text-indent: 2em;">2）为数据访问添加上下文</section><section style="text-indent: 2em;"><span style="text-indent: 34px;">3）建立分离的数据访问安全层</span></section><section style="text-indent: 2em;">4）持续的敏感数据发现和<span style="text-indent: 34px;">分级</span>分类</section><section style="text-indent: 2em;">5）在数据源头保护数据</section><section style="text-indent: 2em;"><span style="text-indent: 2em;">6）开展持续的权限治理</span><br/></section><section style="text-indent: 2em;">7）可在现有环境中部署</section><p><strong><span style="text-indent: 34px;text-align: center;">5. </span><span style="text-indent: 34px;text-align: center;">示例：Satori数据访问平台</span></strong></p><p><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-align: center;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="outline: 0px;max-width: 100%;text-indent: 34px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="text-align: center;text-indent: 34px;"></span></span></span></span></span><strong><span style="text-indent: 34px;text-align: center;">6. 总结：</span><span style="text-indent: 34px;text-align: center;">数据安全新方法与零信任的关系</span><span style="text-indent: 34px;text-align: center;"></span></strong></p><section style="text-indent: 2em;">1）数据安全新方法彻底贯彻了零信任思想</section><section style="text-indent: 2em;">2）零信任是以数据为中心的安全架构</section><section style="text-indent: 2em;">3）美国国防部将零信任应用于数据安全</section><section style="text-indent: 2em;">4）数据访问控制与零信任的区别</section><p><span style="text-indent: 34px;text-align: center;"></span></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-top: 15px;"><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">背景：<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据驱动战略</strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span><strong><span style="font-size: 17px;">与DataSecOps</span></strong><strong style="text-align: left;"></strong></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>1）数据驱动战略与数据驱动型组织</strong></section><section style="margin-top: 15px;white-space: normal;"><strong>数据是一切的中心</strong>。数据的创建、存储、使用，是形成竞争优势和创新的引擎。由于云数据存储和访问技术的飞跃，在很大程度上使<strong>数据成为一种战略资产</strong>。</section><section style="margin-top: 15px;white-space: normal;"><strong>数据驱动战略</strong>已经彻底改变了企业的运营方式，并为那些正确利用它的人带来了惊人的增长。实施<strong>数据驱动</strong><strong>战略</strong>，成为帮助企业进入<strong>数字化转型</strong>下一阶段的关键。</section><section style="margin-top: 15px;white-space: normal;"><strong>数据驱动型组织</strong>，即坚持<strong style="white-space: normal;">数据驱动</strong><strong style="white-space: normal;">战略</strong>的组织，尤其是金融科技和健康科技等受监管行业的组织，开始越来越关注数据湖和数据仓库中日益增长的安全性和合规性挑战。</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.7084639498432602" data-w="638" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d6694848&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMS4QwchOrN2jkKl11wELYu9afFa4O4GyPmmibwbMLexert6BYqEL8Zt2VxOtUsRVHmfuaSf0zQ34Q%2F640%3Fwx_fmt%3Dpng"/></section><p style="white-space: normal;text-align: center;margin-top: 5px;">图1-数据驱动型组织的竞争优势</p><p style="white-space: normal;margin-top: 15px;"><strong>2）数据<strong style="white-space: normal;"><span style="color: rgb(0, 0, 0);">民主化</span></strong>与DataOps</strong></p><section style="margin-top: 15px;"><strong><span style="color: rgb(0, 0, 0);">数据民主化</span></strong><span style="color: rgb(0, 0, 0);">。为了让组织充分利用数据，数据必须是可发现和可访问的。</span><span style="color: rgb(0, 0, 0);"><strong>数据民主化</strong></span><strong>意味着更多的人能够访问更多的数据。</strong>但直到最近，人们还认为数据最好是分开保存，只有少数人能够很好地理解数据并使用它。为了从这些过时的方法过渡到现代方法，人们必须提升对数据的认知。</section><section style="margin-top: 15px;"><strong>DataOps是数据民主化的基石</strong>。<strong>DevOps</strong>致力于成为现代应用程序开发的更好框架。而<strong>DataOps</strong>用于描述在运营<strong style="white-space: normal;">动态数据环境</strong>的组织中处理数据的方式。</section><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.21203228173147468" data-s="300,640" style="" data-type="png" data-w="1363" src="https://wechat2rss.xlab.app/img-proxy/?k=cee6649e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMdQ1ITibpMiaOR1RZ3TyjNTTegKROsCw2lbmvInYhf0CicJ2tg7UO9nUbn7nQcb6Zk8swU24NtiaGDFw%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-top: 15px;">图2-DevOps与DataOps<strong style="white-space: normal;"></strong><strong style="white-space: normal;"></strong></section><p style="margin-top: 15px;white-space: normal;"><strong>3）数据<strong><span style="color: rgb(0, 0, 0);">安全</span></strong>与DataSecOps</strong></p><section style="margin-top: 15px;">组织正在生成、存储、分析前所未有的<strong>数据量</strong>，同时还需要比以往更广泛、更高效的<strong>数据访问</strong>。然而，更多的数据、更多的访问、更多的监管，代表着日益增长的安全、隐私、合规风险。</section><section style="margin-top: 15px;">正如DevOps向DevSecOps的演进，<strong>DataOps向<strong>DataSecOps的演进，也是一种必然。</strong></strong>DataSecOps 是组织<strong>将安全视为其数据运营的一部分</strong>的方式的演变。<strong>DataSecOps</strong>是一种敏捷、整体、安全的嵌入式方法，用于协调不断变化的数据及其用户，旨在提供快速的数据转化价值，同时保持数据的私密性、安全性和良好的治理。DataSecOps应该被视为数据民主化进程的推动者。</section><section style="margin-top: 15px;white-space: normal;">数据驱动战略呼唤新一代数据安全方案。我们需要一种新的方法，<strong>它依赖于完整的数据流可见性、策略执行、丰富的数据访问上下文</strong>，并且可以扩展以满足当今和未来的需求。</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-top: 15px;"><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据安全保护为什么这么难</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;"><strong>1）数据的规模化治理难题</strong><br/></section><section style="margin-top: 15px;white-space: normal;">云让企业能够比以往更轻松地构建大型计算和存储基础设施。很多情况下，云存储运营的新定价模型基于<span style="color: rgb(0, 0, 0);"><strong>查询/访问</strong>而非<strong>存储量</strong></span>。这直接导致，几乎所有拥有在线业务的公司，都以一条阻力最小的路径，快速建立了一个<strong>PB级数据存储</strong>。</section><section style="margin-top: 15px;white-space: normal;">而这又进一步导致，这些平台中的数据保护和数据治理，必须以<strong>大规模方式</strong>进行。而数据治理的所有一切，从发现和<span style="text-indent: 34px;">分级</span>分类，到访问控制和安全，再到策略和审计，都需要<strong>重新发明</strong>，以应对存储的<strong>海量</strong>数据及其生成和使用的<strong>速度</strong>。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>2）为什么数据<span style="text-indent: 34px;">分级</span>分类很难</strong><br/></section><section style="margin-top: 15px;white-space: normal;">敏感数据<span style="text-indent: 34px;">分级</span>分类的重要性毋庸置疑，但数据<span style="text-indent: 34px;">分级</span>分类真地很难：<br/></section><section style="margin-top: 15px;"><strong>数据是一个移动的目标</strong>。在许多情况下，<strong>数据不是先生成再存储</strong>，而是从不同的位置获取，在这些位置它<strong>经历了ETL/ELT过程</strong>。由于ETL/ELT过程，数据通常是一个移动目标，在这些过程中，数据被移动，以<strong>富化、匿名化或经历其他转换</strong>。这些移动可能发生在同一平台内，也可能跨越不同的公共云或数据平台，使得跟踪起来非常复杂。</section><section style="margin-top: 15px;"><strong>数据本身正在发生变化</strong>。当数据从一个地方移动到另一个地方时，它不仅是在旅行，而且自身还会发生变化。您的表中原本没有任何敏感数据，但可能有人不小心添加了敏感个人信息。</section><section style="margin-top: 15px;"><strong>对半结构化数据进行<span style="text-indent: 34px;">分级</span>分类是一项挑</strong><strong>战</strong>。半结构化数据（例如存储在 JSON 文件或数据仓库或数据湖中其他半结构化数据对象中的数据）会增加数据<span style="text-indent: 34px;">分级</span>分类的复杂性。例如，Snowflake表中名为 event_data 的列，可能包含不同类型的半结构化对象，并且在某些情况下存在包含敏感数据的条目。对于半结构化数据，遍历数据以发现敏感数据变得更加困难。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>3）仅凭日志是远远不够的</strong></section><section style="margin-top: 15px;white-space: normal;"><strong>日志</strong>通常非常重要。<strong>数据访问日志极其重要，因为它们可以阐明数据访问情况。数据访问日志</strong>是由数据库引擎生成的日志，提供了有关数据库事务的信息。</section><section style="margin-top: 15px;white-space: normal;"><strong>虽然数据访问日志确实存在、也非常有用，但真正理解它们非常具有挑战性</strong>：</section><section style="margin-top: 15px;"><strong><span style="color: rgb(0, 0, 0);">标准不一</span></strong><span style="color: rgb(0, 0, 0);">：数据访问日志一般没有标准化，</span>粒度级别也各不相同。<span style="color: rgb(0, 0, 0);">各种日志经常记录在不同的数据存储中</span>，而从不同的数据存储收集日志，有时需要大量工作来统一日志。</section><section style="margin-top: 15px;"><strong>设置不明</strong>：数据访问日志并不总是“默认开启”，在某些情况下，它们必须进行设置和配置，包括通过设置特定的ETL流程来“照料”它们。</section><section style="margin-top: 15px;"><strong>信息不足</strong>：有时日志并不包含您以为该有的信息，例如，有时数据访问用户实际上并不是数据消费者，而是分析框架使用的<strong>通用账户</strong>。找出是谁发送了查询，可能需要<strong>关联</strong>来自其他系统的日志，这非常复杂甚至不可能实现。此外，在大多数情况下，<strong>数据访问日志不包含提取数据的实际位置</strong>（数据库、schema、表），想从查询中了解此信息是一项艰巨任务，因为一些数据消费者并没有运行“SELECT * FROM table”，而是一个 1000 行的分析查询，其中包括多个子查询。</section><section style="margin-top: 15px;"><strong>缺乏上下文</strong>：通常<strong>缺乏</strong><strong>理解这些日志所需的关键上下文</strong>，如关于用户访问数据的信息、关于被访问数据的性质的信息、关于什么被认为是正常的和符合组织策略的信息。这些信息通常散布各处，并跨越各种与日志不相关的工具。<br/></section><section style="margin-top: 15px;white-space: normal;">这些问题导致的结果是：仅有本机日志是远远不够的，组织仍然<strong>缺乏数据可见性</strong>。</section><section style="margin-top: 15px;white-space: normal;"><strong>4）数据存取方式的演变<br/></strong></section><section style="margin-top: 15px;white-space: normal;">过去，企业依靠精通SQL的分析师，直接从数据库查询信息。他们使用<strong>客户机-服务器接口</strong>直接访问数据库，并使用<strong>数据库的用户管理系统</strong>验证其访问权限。</section><section style="margin-top: 15px;white-space: normal;">后来，随着组织内部对数据需求的增长，人们发明了更复杂的客户机，以简化分析师的工作。这在很大程度上需要使用<strong>GUI</strong>（图形用户界面）抽象出SQL和数据库连接。</section><section style="margin-top: 15px;white-space: normal;">再后来，随着这些客户机在组织中的应用越来越广泛，通过将其部署为<strong>Web应用程序</strong>来进行大规模供应变得越来越容易。</section><section style="margin-top: 15px;white-space: normal;">再后来，随着企业迁移到云，这些部署转变为<strong>即服务交付</strong>。</section><section style="margin-top: 15px;white-space: normal;"><strong>导致的改变</strong>。从少数单用户桌面客户端访问组织中数据，转变为大量用户使用基于Web的应用程序甚至移动应用程序，这使得组织更<strong>难以使用数据库的用户管理系统</strong>为用户提供服务。组织将身份验证转向应用程序，并开始使用<strong>服务帐户（service accounts）</strong>将应用程序连接到数据库，而不是同时在数据库和应用程序两层中为每个用户调配资源。</section><section style="margin-top: 15px;white-space: normal;"><strong>数据访问归因问题。</strong>数据访问由不同的<strong>工具</strong>驱动，包括自主开发的<strong>应用程序、BI工具、命令行界面、脚本</strong>。在大多数情况下，必须创建<strong>服务账户</strong>才能授予和管理这些工具的数据访问权限。这时，<strong style="white-space: normal;">连接到数据存储的用户是为工具本身配置的账户，而不是工具背后的实际员工</strong>。虽然从用户管理的角度来看很方便，但这意味着<strong>数据访问不能归因于驱动它的真实用户</strong>。</section><section style="margin-top: 15px;white-space: normal;"><strong>5）难以设置的访问权限</strong><br/></section><section style="margin-top: 15px;white-space: normal;">在许多组织中，<strong>数据和分析团队</strong>被授予非常广泛的数据访问权限。虽然广泛的数据访问对于企业的创新和成功必不可少，但由于<strong>缺乏访问权限控制</strong>，因此很难降低数据泄露的风险。</section><section style="margin-top: 15px;white-space: normal;">一个常见的情况是<strong>服务帐户的特权过高。</strong><strong>服务帐户<strong>（service accounts）</strong></strong>是应用程序用来代表其用户访问资源的一种特殊类型的身份。服务帐户不代表任何特定用户，它代表需要访问资源的任何用户。对于数据存储，即数据库、数据仓库、数据湖、其他系统（如缓存、搜索引擎、消息队列等），这意味着服务帐户通常可以访问数据存储中的所有数据。这将导致两个重大后果：<br/></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>首先，<strong>数据访问的安全控制已从数据存储层转移到应用层</strong>，这意味着构建、维护、监控安全控制的责任，已从安全团队转移到工程团队。</p></li><li><p>其次，数据已经变得更加暴露——要么是<strong>应用程序中的安全漏洞</strong>（如安全控制或SQL注入中的漏洞），要么是使用<strong>服务帐户的凭据</strong>并直接连接到数据存储，从而完全绕过应用程序。</p></li></ul><section style="margin-top: 15px;white-space: normal;">过度放纵的反面则是<strong>过度</strong><strong>限制数据访问</strong>。这当然违背了数据驱动战略的目标，所以不能被视为合适的替代方案。</section><section style="margin-top: 15px;white-space: normal;"><strong>6）新法规要求组织重新思考其数据战略</strong><br/></section><section style="margin-top: 15px;">随着数字转型，企业正在走向在线，每天生成、存储、处理和交换的个人信息数量惊人。出于对个人和一般敏感信息的安全和隐私的担忧，许多司法管辖区引入了新的法规，如国内的《数据安全法》和《个人信息保护法》、欧盟的GDPR、美国加利福尼亚的CCPA。</section><section style="margin-top: 15px;">随着大量罚款和客户对其数据拥有的权利的明确定义，以及组织在收集、存储、使用这些数据时必须遵守的要求，这些新法规极大地改变了组织对数据安全、隐私、治理的思考方式。</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-top: 15px;"><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">保护敏感数据的现有方法</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>1）数据编目与分级分类</strong><br/></section><section style="margin-top: 15px;"><strong>大多数数据治理计划，都是从试图了解数据在组织中的位置以及正在生成、处理、存储、读取的数据类型开始的</strong>。</section><section style="margin-top: 15px;">在大多数情况下，这一过程要求所有利益相关者合作并共享他们所知道的信息，以构建所有<strong>数据流的地图</strong>。包括谁正在访问数据，他们正在访问什么类型的数据，以及数据存储在哪里。对于大型组织来说，这本身就是一个巨大的挑战，因为团队成员分布在不同的地理位置和不同的时区。通常情况下，这些计划启动缓慢，往往中途失败。</section><section style="margin-top: 15px;"><span style="font-size: 17px;">另一个障碍是<strong>数据是一个移动的目标</strong>——特别是在云环境中，生成新的数据存储既快速又简单，而传统的IT治理效果较差。当这些举措产生结果时，背景和环境可能已经改变，组织可能在不知不觉中掌握更敏感的信息。</span></section><section style="margin-top: 15px;">即使在了解了敏感信息的位置之后，组织仍需努力使该信息具有可操作性。而<strong>依赖数据防泄漏（DLP）解决方案来提供上下文通常太少、太晚</strong>。<br/></section><section style="margin-top: 15px;"><strong>2）访问控制和权限管理<br/></strong></section><section style="margin-top: 15px;">一旦组织知道他们拥有什么样的敏感信息以及这些信息在哪里，就有必要建立防护栏和边界，限制只有需要的人才能访问这些信息。</section><section style="margin-top: 15px;">虽然有很多工具可以帮助组织管理对资源的访问，<strong>例如数据存储，但它们并不了解数据</strong>。<strong>试图在数据存储schema的特定部分上定义访问控制，是非常具有挑战性的：</strong>半结构化和非结构化数据存储没有schema，而且，就基于模式的数据存储而言，为每个用例的每个用户，在表和列级别管理细粒度权限的过程，在规模上是一个无法克服的挑战。</section><section style="margin-top: 15px;"><span style="font-size: 17px;"></span></section><section style="margin-top: 15px;"><strong>3）掩蔽、加密、<span style="text-indent: 34px;">符号</span>化<br/></strong></section><section style="margin-top: 15px;"><strong>一些组织遵循复制敏感数据的策略</strong>，并应用各种技术<strong>消除静止数据的风险，例如<strong style="white-space: normal;">掩蔽</strong>、加密、<span style="text-indent: 34px;">符号</span>化</strong>——例如，在掩蔽其中的任何敏感信息的同时，为开发团队提供生产数据库的副本以供调试。<br/></section><section style="margin-top: 15px;"><strong>虽然这种方法对特定用例有效，但由于缺乏灵活性和由此产生的开销，在规模上失败了。为每个用例创建一个数据副本，应用所需的转换来保护它，并授予对它的访问权，是一个缓慢的过程。每当克隆数据存储中需要新字段时，都需要调整并重新运行复制过程。此外，这种设计方法会产生更多的数据</strong>，从而导致更大的风险、更大的运营开销和更高的基础设施成本。<br/></section><section style="margin-top: 15px;">总之，在过去几十年中，保护敏感数据的现有策略是一个一个地建立起来的，缺乏整体性。它们会导致巨大的操作开销，并且只能解决部分问题。考虑到各组织正在云中采用新的数据存储技术，并在越来越严格的隐私法规下处理比以往任何时候都多的数据，寻求一种新方法是很必要的。<br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-top: 15px;"><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">数据保护和治理的新方法</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="white-space: normal;margin-top: 15px;"><br/></p><h1 style="margin-top: 15px;"><strong style="font-size: 17px;">新一代数据安全方案</strong><span style="font-size: 17px;">应遵循以下</span><strong style="font-size: 17px;">原则</strong><span style="font-size: 17px;">：</span></h1><p style="margin-top: 15px;white-space: normal;"><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">1）执行</strong><span style="color: rgb(0, 0, 0);"><strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong>动态和细粒度数据访问控制</strong></strong></span></p><h1 style="margin-top: 15px;white-space: normal;"><span style="font-size: 17px;">必须意识到，解决数据访问安全挑战，不能以牺牲业务输出为代价。</span><span style="font-size: 17px;">一个好的解决方案</span><span style="font-size: 17px;">必须既能确保企业的安全，又不会减慢企业的速度。</span><br/></h1><section style="margin-top: 15px;white-space: normal;">为了解决这个问题，组织需要能够了解他们的敏感数据在哪里，尤其是当它与数据湖和数据仓库中的其他数据混合时，并跟踪其消费者的使用情况，还要能够对用户访问敏感数据和受监管数据设置限制。</section><section style="margin-top: 15px;white-space: normal;">为了真正解决数据安全问题，组织需要能够强制执行<span style="color: rgb(0, 0, 0);"><strong>动态和细粒度数据访问控制</strong></span>，可以保护敏感数据，揭露行为异常。这才是<strong>新一代数据安全方案的基本思想</strong>。<br/></section><p style="margin-top: 15px;white-space: normal;"><strong>2）为数据访问添加上下文</strong></p><section style="margin-top: 15px;white-space: normal;">数据存储库本身就是一个宇宙。如果没有专门的平台，企业就不可能高效跟踪内部发生的事情。组织希望回答一些基本问题，例如谁在访问他们的数据、正在访问哪些类型的数据、这些数据的用途。</section><section style="margin-top: 15px;white-space: normal;">实现这一目标的最佳且唯一的方法，是<strong>为数据访问添加</strong><span style="color: rgb(172, 57, 255);"><strong><strong style="white-space: normal;">用户、数据、意图上下文</strong></strong></span><strong>，即将用户身份、数据类型、访问意图的信息关联起来</strong>。 这些类型的上下文，通常存在于多个系统中。如组织的<strong>身份系统</strong>提供有关人员及其群体的信息；<strong>数据目录和</strong><strong>主数据管理系统</strong>包含有关数据集及其业务上下文的信息；<strong>数据存储</strong>维护与访问相关的日志；<strong>数据库权限</strong>则上下文化授权访问。</section><section style="margin-top: 15px;white-space: normal;">为此，至少需要<strong>将标签分为两类：身份标签和数据标签</strong>。<strong>身份标签</strong>提供有关尝试访问数据的实体的上下文信息（例如，组织单位、位置，甚至特定帐户）。<strong>数据标签</strong>提供有关所访问数据的上下文信息。大多数上下文信息，默认由分级分类引擎生成，但客户也可以自定义。</section><section style="margin-top: 15px;white-space: normal;"><strong>3）建立分离的数据访问安全层</strong></section><section style="margin-top: 15px;white-space: normal;">每个组织都以不同的方式处理数据保护。可以将它们提炼为<strong>两种方法</strong>：</section><ul class="list-paddingleft-2" style="width: 577.417px;white-space: normal;"><li><p>1）<strong>外挂安全</strong>：在现有系统之外，<strong>挂接</strong>安全/隐私控制；</p></li><li><p>2）<strong>设计安全</strong>：通过设计，<strong>嵌入</strong>安全/隐私。</p></li></ul><section style="margin-top: 15px;white-space: normal;">就流行偏好而言，当今大多数公司都倾向于<strong>外挂安全</strong>。从表面上看，这似乎是阻力最小的路径，因为它容易集成到他们已有的系统架构和运营中。</section><section style="margin-top: 15px;white-space: normal;">但实际上，采用<strong>设计安全</strong>方式，建立一个与数据架构分离的数据访问安全层，可以在不限制访问的情况下确保数据安全，使得现代企业更有可能获得成功。</section><section style="margin-top: 15px;white-space: normal;"><strong>将访问控制与数据平台分离</strong>，是与DataSecOps方法保持一致的唯一方法，是阻力最小和功效最大的真正途径。因此，必须采用可跨任何数据平台或API工作的<strong>通用数据访问服务</strong>。</section><section style="margin-top: 15px;white-space: normal;">通过<strong>建立分离的数据访问安全层</strong>，将访问控制（以及访问控制日志记录）与数据存储基础设施分离。这样，设置访问控制策略以及审计它们，就可以跨不同平台实现统一，从而获得<strong>跨多个数据存储的访问管理</strong>的统一体验。</section><section style="margin-top: 15px;white-space: normal;"><strong>4）进行持续的敏感数据发现和<strong style="white-space: normal;">分级</strong>分类</strong></section><section style="margin-top: 15px;white-space: normal;">敏感信息往往会出现在意料不到的地方，当你刚刚绘制完成<strong>敏感数据地图</strong>后，可能发现敏感数据随即出现在新的位置。这正是墨菲定律想表达的意思。</section><section style="margin-top: 15px;"><strong style="white-space: normal;">数据经常变化</strong>，只有通过<strong style="white-space: normal;">持续的可见性和洞察力</strong>，才能大规模地保护和治理数据，比如<strong>数据盘点、数据访问审计、数据访问控制</strong>等。<br/></section><section style="margin-top: 15px;">为此，需要进行持续的敏感数据发现和分级分类。根据不同的数据类型，可以采取的具体方法包括：<strong>字典匹配、模式匹配、算法匹配、机器学习</strong>等。<br/></section><section style="margin-top: 15px;"><strong>对半结构化数据进行持续分级分类很重要</strong>。在许多数据分类中，<strong>半结构化数据</strong>通常被忽略或统一归为一个块（例如，包含 1,000 个不同值的消息，被标记为“电子邮件”，仅仅因为其中一个值是电子邮件地址）。由于半结构化数据在许多情况下不一致，因此对其进行持续分级分类很重要。例如，半结构化数据可能包含随时间添加的额外键，而没有任何数据库schema变更。</section><section style="margin-top: 15px;"><strong>数据分级分类的粒度级别</strong>。所需的粒度级别有两个：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>位置级粒度</strong>：可以细化到特定的<strong>数据存储、数据库、schema、表或列</strong>。要求了解位于特定列内的半结构化数据中不同数据类型的位置，可能更加细化。</p></li><li><p><strong>数据类型粒度</strong>：在大多数情况下，至少需要定义分类数据的<strong>类别</strong>。在许多情况下，要求更加具体，并将数据分类为特定<strong>类型</strong>，例如电话号码、姓名、血型、患者 ID 或社会保障号码。</p></li></ul><section style="margin-top: 15px;"><strong>5）在数据源头保护数据</strong></section><section style="margin-top: 15px;"><strong>避免传统的</strong><strong>数据<strong>副本方法</strong></strong>。传统数据控制的一个主要问题在于，许多组织都会为不同的用例（例如，掩蔽和非掩蔽数据集）<strong>复制schema</strong>。这种粗糙的方法，会导致过时的数据、繁冗而缓慢的审批流程，以及每种使用模式的数据仓库数量不断增加。对于具有合理数据规模的组织来说，<strong>复制数据或复制基础设施</strong>都是不可扩展或不切实际的。</section><section style="margin-top: 15px;"><strong>基于上下文的数据访问控制</strong>，通过强制执行多个策略，来避免创建数据的副本。这些策略负责解释每种使用模式，可以根据每种单独的使用模式，掩蔽、减少、转换数据，而无需修改schema或数据。</section><section style="margin-top: 15px;">尽量避免使用<strong>静态数据转换</strong>（例如，用掩蔽的电子邮件地址，替换数据集中的所有电子邮件地址），而是利用<strong>动态数据转换</strong>在源头保护敏感数据，例如，当用户查询不应暴露于个人识别信息（PII）的电子邮件地址时，可以掩蔽这些地址。这确保了组织只存储他们需要的数据，并允许<strong>通过配置谁可以访问数据而不是运行在线复制过程</strong>，以更灵活的方式提供对数据的访问。</section><h2 style="margin-top: 15px;"><strong style="font-size: 17px;">6）开展持续的权限治理</strong><br/></h2><section style="margin-top: 15px;">无法贯彻最小权限原则，是许多组织面临的问题。<strong>权限几乎是</strong><span style="color: rgb(172, 57, 255);"><strong>单向</strong></span><strong>发展的</strong>——<strong>请求增加权限的情况频繁发生，但很少会有人主动请求删除访问权限</strong>。这导致，<strong>权限的膨胀速度，会比面团发酵还要快</strong>。</section><section style="margin-top: 15px;">为解决权限回收问题，<strong>应分析用户权限（用户有权使用什么）和实际数据访问（用户实际使用什么）之间的差距。然后对差距进行优先级排序</strong>，以便及时回收不必要的权限。</section><section style="margin-top: 15px;"><strong>将数据授权给人，而非授权人到数据</strong>。目前最流行的数据授权方式是<strong>RBAC</strong>（基于角色的访问控制）。RBAC是一个<strong>授权用户访问数据</strong>的系统，它可以定义<strong>哪些角色</strong>可以访问<strong>哪些位置</strong>的数据。事实上，<strong>数据位置是不明确的</strong>，因为数据在不断地移动。此外，在一个快速发展的组织中，角色也未必准确定义其工作范围。因此，公司不得不实施<strong>手动</strong>流程，旨在验证控制的准确性，这就必然降低了流程速度。</section><section style="margin-top: 15px;">因此，应该考虑<strong>将数据授权给人</strong>的选项。这种方法可以<strong>定义感兴趣的数据类型以及获取访问权限所需的内容</strong>。这种替代方案需要一种更细粒度的授权机制，该机制考虑到数据和访问属性。<strong>ABAC</strong>（基于属性的访问控制）就是这样一种方法，它允许更灵活的策略。再加上一个<strong>数据访问层</strong>，不仅可以控制访问，还可以控制返回的数据和涉及的过程。这样，就使得对于不同使用模式的维护，可以<strong>从手动转向自动</strong>。</section><section style="margin-top: 15px;"><strong>7）可在现有环境中透明化部署</strong><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>避免重建数据基础设施</strong>。大多数组织不会仅仅为了采用数据安全解决方案，而重新构建其数据基础设施。<strong>通过替换部分数据基础设施（如存储或查询引擎）或依靠广泛部署应用程序或端点代理来提供安全价值的解决方案，既很难实施，又很难被欣赏</strong>。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>在现有环境中透明化部署</strong>。数据安全不是一个全新市场，企业已经投资建立自己的数据平台和流程。因此，数据安全解决方案必须能够在不中断企业业务的情况下适应现有环境，并在不影响现有使用模式和工具的情况下<strong>集成到现有基础设施</strong>中。最重要的是，<strong>目标必须是通过简单、高效、广泛的</strong><span style="color: rgb(172, 57, 255);"><strong>数据访问</strong></span><strong>，来优化他们的数据运营</strong>。</section><section style="margin-top: 15px;white-space: normal;">按照这个逻辑，<strong>一个好的数据保护和数据治理解决方案</strong>，必须能够实现正常的数据访问，而不是中断或产生负面影响。然而，<strong>一个伟大的解决方案，将使数据访问比以前更容易、更高效、更广泛！</strong> </section><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">示例：Satori 安全数据访问<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;white-space: normal;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>Satori是</strong><strong>RSA 2021大会的创新沙盒十强决赛入围者</strong>。Satori在日语中有“<strong style="white-space: normal;">顿悟</strong>”之意。Satori秉持<strong>DataSecOps</strong>理念，引入了位于数据消费者和数据存储之间的<strong>通用数据访问</strong>服务的概念。毫无疑问，Satori<strong>通用数据访问平台</strong>是上述<strong>数据安全新方法</strong>的典型示例。</section><section style="margin-top: 15px;white-space: normal;">Satori提出了一种新的数据安全方法，提供了<strong>对数据和数据流的持续可见性</strong>，实施必要的安全控制，强制执行合规性和隐私政策，同时使合法访问变得简单、快速、高效。Satori通过<strong>将用户/应用程序身份与实时数据发现、分级分类、行为分析相结合</strong>，实现了这一点。</section><section style="margin-top: 15px;white-space: normal;">Satori 充当<strong>数据消费者</strong>（用户/应用程序）和<strong>数据存储</strong>之间的<span style="color: rgb(172, 57, 255);"><strong>数据访问层</strong></span>，也是一个<strong>上下文感知层</strong>，其方式与<strong>代理</strong>类似。它检查每个事务，对动态数据进行分级分类，通过 IAM 解决方案或数据存储用户和角色配置添加身份上下文，并为所有云数据存储提供精细的访问控制策略和集中分析。<br/></section><section style="margin-top: 15px;white-space: normal;">Satori 的核心是一个<span style="color: rgb(172, 57, 255);"><strong>透明代理</strong></span><strong>服务</strong>，数据消费者连接到它，而不是连接到实际的数据存储本身。<strong style="white-space: normal;">Satori 对其数据用户是透明</strong><strong style="white-space: normal;">的</strong>，因此不需要对业务智能 (BI) 或分析工具进行任何更改，也不会改变数据用户使用数据的方式（即查询或命令中没有变化）。<strong style="white-space: normal;">Satori 对数据存储也是透明的</strong>，因此不会改变数据存储本身中的任何内容（即没有创建视图或schema），身份认证、授权、审计机制也保持不变。</section><section style="margin-top: 15px;white-space: normal;">Satori 通过下述<strong>上下文</strong>，富化每个数据活动：<br/></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>身份</strong>：Satori 监控到数据存储的新连接的创建，并使用该信息在组织的<strong>IAM (身份和访问管理) </strong>系统中查找用户的配置文件。</p></li><li><p><strong>数据</strong>：Satori 会同时观察<strong>查询</strong>和<strong>结果集</strong>，以对包含敏感信息（如姓名、电子邮件地址、社会保障号码）的<span style="color: rgb(0, 0, 0);">事务</span>进行分类。</p></li><li><p><strong>行为</strong>：Satori 分析环境中的真实用户访问，以了解正常访问是什么样的，同时还提供了一套丰富的开箱即用的<strong>行为策略</strong>，以促进数据访问安全。</p></li></ul><p> </p><section style="margin-top: 15px;text-align: center;"><img class="rich_pages wxw-img" data-ratio="0.7256235827664399" data-w="882" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2632d46a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPMdQ1ITibpMiaOR1RZ3TyjNTTjiaTIic4icRsZEe8Aa7kiaW4ianicsXA6sOiar8oEA2QwpNtXVkvNKiaH0zib4g%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;text-align: center;">图3-Satori通用数据访问平台/服务</section><section style="margin-top: 15px;">Satori架构解决可靠性和低延迟问题的方法是，<strong>将数据流量分成</strong><strong>两个数据路径</strong>：代理和分析。<strong>代理</strong>意味着将字节从数据消费者传输到数据存储；<strong>分析</strong>是运行算法和策略引擎的地方。每条路径都由一组单独的计算资源处理，更重要的是，由具有不同代码库和发布节奏的单独软件处理。</section><section style="margin-top: 15px;"><strong>对于代理</strong>，Satori 使用Nginx，这是一种众所周知的代理软件。使用 Nginx 的开箱即用功能，来代理 TCP 和 HTTP 流量并终止 TLS 连接。每个 Satori 部署都包含一组高度可用的 Nginx 代理服务器，作为 Kubernetes 集群中的容器。数据消费者和数据存储之间的连接仅通过 Nginx。</section><section style="margin-top: 15px;"><strong>对于分析</strong>，Satori 使用Rust构建了“分析器”（Analyzer） ，Rust是一种专注于安全性、并发性、高性能的系统编程语言。分析器不在数据消费者和数据存储之间的数据路径中。相反，它从 Nginx 接收流量捕获，并异步处理它们。根据应用于连接的策略，分析器可以指示 Nginx 终止连接、阻止查询、返回空结果集、掩蔽敏感数据。 </section><p><br/></p><p><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">总结：数据安全新方法与零信任的关系<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;">简单总结下数据安全新方法与零信任的关系：</section><section style="margin-top: 15px;"><strong>1）数据安全新方法彻底贯彻了零信任思想</strong></section><section style="margin-top: 15px;">数据安全新方法本质上是一种新型的数据访问控制方法，而数据访问控制必然依赖于零信任方法。作为新一代数据访问控制的代表，<strong style="white-space: normal;">Satori正在全面实现基于零信任的数据访问控制服务。</strong></section><section style="margin-top: 15px;"><strong>2）零信任是以数据为中心的安全架构</strong></section><section style="margin-top: 15px;">这是零信任与<strong>以网络为中心</strong>的传统安全模型的主要区别。</section><section style="margin-top: 15px;">数据是零信任的支柱目标之一。在《美国联邦政府零信任战略》中支柱目标包括：支柱目标1-身份；支柱目标2-设备；支柱目标3-网络；支柱目标4-应用；支柱目标5-<strong>数据</strong>。本质上，实现数据安全，是零信任的终极目标。</section><section style="margin-top: 15px;white-space: normal;"><strong>3）美国国防部将零信任应用于数据安全</strong></section><section style="white-space: normal;margin-top: 15px;">不妨看看美国国防部（DoD）面向数据安全的零信任架构。<br/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-fileid="100010856" data-ratio="0.5056360708534622" data-w="1242" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=4cfad397&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPP1WaQzz8OcWP4Aj2ib8Z92ojylpss6QWeXL2oCFsbh1JETiaj7micDibMhUCsgKxNqribnmTwwAatChCQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图4-DoD面向数据安全的零信任架构</section><section style="margin-top: 15px;white-space: normal;">从图中可以看到，有4道授权决策点，但考虑到第1道授权包含了<strong>人</strong>和<strong>设备</strong>两种情况，所以实际上可以展开成5道授权决策点。如下图所示：</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-fileid="100010857" data-ratio="0.45517241379310347" data-w="1160" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=2c33a447&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPP1WaQzz8OcWP4Aj2ib8Z92ohiaog68MZssFibIJh9iccmGXvVexWVjxuTJF2kG50osjCVvL5Mbp326FQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图5-逐层深入的数据授权过程</section><section style="margin-top: 15px;white-space: normal;">从上图可见，5道授权决策点依次是：<strong>用户-&gt;设备-&gt;网络-&gt;应用-&gt;数据</strong>。而通常意义上的零信任，主要是实现了前面的4道授权。而第5道数据授权，才是数据访问控制的核心。数据授权的基本原理如下图所示：</section><section style="margin-top: 15px;white-space: normal;text-align: center;"><img class="rich_pages wxw-img" data-fileid="100010858" data-ratio="0.5098684210526315" data-w="1216" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=5f5e3067&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPP1WaQzz8OcWP4Aj2ib8Z92oKa8qVlJcF32kfM8E0HQlFZLUN7CK0lxeMpXSnxcHzN8OVSaMT4Dc5g%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;">图6-数据访问控制的基本原理</section><p style="margin-top: 15px;white-space: normal;">数据访问控制与之前几道访问控制的重要区别在于：之前的几道网关都是<strong>功能级</strong>的访问控制；而数据访问网关是<strong>数据级</strong>的访问控制。数据访问网关通过数据访问策略引擎，实现数据库的表级、行级、列级、字段级的数据访问控制。这是其它的网关通常无法实现的能力，也是数据安全中最值得重视的能力。</p><section style="margin-top: 15px;white-space: normal;"><strong>4）数据访问控制与零信任的区别</strong></section><section style="margin-top: 15px;white-space: normal;">如果一定要分辨数据访问控制与零信任访问控制的区别，可以简单地认为：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>保护对象</strong>：零信任保护的是<strong>业务/应用访问</strong>；数据访问控制保护的是<strong>数据访问</strong>。</p></li><li><p><strong>实现方式</strong>：零信任的实现方式通常是<strong>应用代理</strong>；数据访问控制的实现方式通常是<strong>数据代理</strong><strong style="white-space: normal;"></strong>。</p></li><li><p><strong>控制粒度</strong>：零信任访问控制的粒度通常是<strong>功能级</strong>；而数据访问控制的粒度必然是<strong>数据级</strong><strong style="white-space: normal;"></strong>。<br/></p></li></ul><section style="margin-top: 15px;white-space: normal;">但其实，以笔者观点看，<strong>数据访问控制</strong>是零信任的<strong>最后环节</strong>和<strong>终极目标</strong>。正如图5（<span style="text-align: center;">逐层深入的数据授权过程</span>）所反映出的，彻底的零信任方案应该包含数据访问控制。</section><section style="margin-top: 15px;white-space: normal;">此外，数据安全与零信任还有个相似的性质在于：它们都超越了传统的安全领域。零信任渗透到<strong>身份治理</strong>领域；数据安全扩展到<strong>数据治理</strong>领域。而这两种治理活动，都需要足够的积累和沉淀。</section><p style="white-space: normal;margin-top: 15px;">未来已来，不谈<span style="text-align: left;">零信任，何谈数据安全！这就是为什么必须</span>在<strong>新一代数据安全框架</strong>中，为零信任留出半壁江山。<br/></p><p style="white-space: normal;margin-top: 15px;"><br/></p><section style="margin-top: 15px;white-space: normal;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></section>



<p><a href="2247494522">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4b07ac54&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494522%26idx%3D1%26sn%3D863d352d7c890967f4333820f0adaa25%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 28 Nov 2021 14:43:00 +0800</pubDate>
    </item>
    <item>
      <title>美国国防部零信任实施方案：Thunderdome（雷霆穹顶）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494496&amp;idx=1&amp;sn=4898d7237fecce4e148941978a13be6d</link>
      <description>雷霆穹顶：雷霆之上，穹顶之下。</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2021-11-07 08:53</span> <span style="display: inline-block;"></span>
</p>

<p>雷霆穹顶：雷霆之上，穹顶之下。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c04357b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPOgg3KYFqz1B8YU6m3dAkJSLdrskqptglAxb06rLhacrxeoQr7SUfPanb9Iaia7icJuAo3ibaw9Te46g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<span style="color: rgb(0, 0, 0);"><strong>4000</strong></span>字  <span style="color:#000000;"><strong>6</strong></span>图表  阅读约<span style="color:#000000;"><strong>10</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;">在美国国防部旗帜鲜明地宣布<strong>零信任战略</strong>和发布<strong>零信任参考架构</strong>之后，<span style="text-align: left;">国防部</span>开始正式向<strong>零信任实施方案</strong>快速推进。<span style="text-align: left;">美国国防信息系统局（<strong>DISA</strong>）</span>提出的<strong style="text-align: left;white-space: normal;">Thunderdome（雷霆穹顶）</strong>，正式成为<strong>国防部</strong><span style="color: rgb(172, 57, 255);"><strong style="text-align: left;white-space: normal;">零信任实施阶</strong></span><span style="color: rgb(172, 57, 255);"><strong style="text-align: left;white-space: normal;">段</strong></span><strong style="text-align: left;white-space: normal;">的急先锋</strong><span style="text-align: left;">。</span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;">DISA已经向行业合作伙伴</span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>征集</strong></span><span style="text-align: left;"><strong><span style="text-align: left;">关于</span></strong><strong style="text-align: left;white-space: normal;">Thunderdome零信任实施方案的白皮书</strong><span style="text-align: left;">。DISA希望，通过<span style="text-align: left;">授予</span><strong style="text-align: left;white-space: normal;">25个SD-WAN站点</strong><span style="text-align: left;">和</span><strong style="text-align: left;white-space: normal;">5000个用户的试点范围</strong><span style="text-align: left;">，</span>在</span><strong style="text-align: left;white-space: normal;">六个月内</strong><span style="text-align: left;">，</span><span style="text-align: left;">为具有</span><strong style="text-align: left;white-space: normal;">客户边缘安全栈</strong><span style="text-align: left;">和</span><strong style="text-align: left;white-space: normal;">应用程序安全栈</strong><strong><span style="text-align: left;">原型</span></strong><span style="text-align: left;">的</span></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>SASE</strong></span><span style="text-align: left;"><span style="text-align: left;">（安全访问服务边缘）和<strong>SD-WAN</strong>（软件定义广域网）架构，提供初始的</span><strong style="text-align: left;white-space: normal;">最小可行产品（MVP）</strong><span style="text-align: left;">。而对这些能力的改进和运行实施，将一直计划到</span><strong style="text-align: left;white-space: normal;">2025年</strong><span style="text-align: left;">。</span></span></p><p style="text-align: left;margin-top: 10px;"><span style="text-align: left;"><span style="text-align: left;">另一方面，国防部首席信息官在2021年夏天已经</span><strong><span style="text-align: left;">决定取消JRSS</span></strong><span style="text-align: left;">（联合区域安全栈）计划，并寻找替代计划。而在<span style="font-family: PingFangSC-light;letter-spacing: 2px;text-align: left;background-color: rgb(255, 255, 255);">2021年10月</span>召开的<strong>2021年度TechNet Cyber会议</strong>，进一步明确将</span></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>Thunderdome</strong></span><span style="text-align: left;color: rgb(172, 57, 255);"><strong>作为JRSS的替代方案</strong></span><span style="text-align: left;">。</span></p><p style="text-align: left;margin-top: 10px;">简而言之，<strong style="text-align: left;white-space: normal;">Thunderdome</strong><span style="text-align: left;">就是美国国防部的</span><span style="color: rgb(172, 57, 255);"><strong style="text-align: left;white-space: normal;">零信任/SASE实施原型</strong></span><span style="text-align: left;">。</span>它的提出，实锤了三件事：一是国防部<strong>网络架构向零信任和SASE演进</strong>；二是国防部零信任工作正式进入<strong>落地试点阶段</strong>；三是<strong>以SASE架构替代JRSS中间层安全</strong>。</p><p style="text-align: left;margin-top: 10px;">值得提醒的是，由于SASE的网络重构属性，<strong style="text-align: left;white-space: normal;">Thunderdome</strong><strong style="text-align: left;white-space: normal;">试点或将</strong><strong style="text-align: left;white-space: normal;">导致对国防部信息网络的</strong><span style="text-align: left;color: rgb(172, 57, 255);"><strong>彻底重构</strong></span><span style="text-align: left;">。</span></p></section></section></section></section></section><section style="text-align: left;margin-top: 15px;"><strong>关键词</strong>：<strong><span style="text-align: left;">RWP</span></strong>（<span style="text-align: left;">白皮书请求</span>，<span style="letter-spacing: 2px;">Request for White Paper</span>）；<strong>DISA</strong>（国防信息系统局）；<strong>SASE</strong>（安全访问服务边缘）；<strong>JRSS</strong>（联合区域安全栈）；<strong style="text-align: left;white-space: normal;">ICAM</strong>（身份、凭证与访问管理）</section><section style="text-align: center;margin-top: 15px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><p>1.背景概述<br/></p><p>2.战略定位</p><p>3.主要意图<br/></p><p>4.技术关注度</p><p>5.技术要求</p><p>6.实施计划</p><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">背景概述<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;white-space: normal;">2020年11月，笔者曾在<span style="color: rgb(0, 82, 255);">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247493835&amp;idx=1&amp;sn=2a43798941f34bdff4729b9f07250852&amp;chksm=97fa35ada08dbcbb443f2ba9139fd0ece7312580cd809158acf858867fe36d9503d2bafa4a04&amp;scene=21#wechat_redirect" textvalue="美国国防部零信任的支柱" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">美国国防部零信任的支柱</span></a><span style="color: rgb(0, 82, 255);">》</span>一文中，展示了美国<strong>国防部网络架构的</strong><strong>三次演进</strong>，并指出<strong>第3次演进</strong>是2020年代的<strong>软件定义边界（SDP）</strong>。</section><section style="margin-top: 15px;white-space: normal;">随着时间推移，DISA（国防信息系统局）进一步强化了这种演进思路，寻求<span style="color: rgb(172, 57, 255);"><strong>在SASE（安全访问服务边缘）安全框架下实施零信任</strong></span>。<span style="letter-spacing: 2px;"><strong>2021年7月</strong>，DISA在开始发布</span><span style="color: rgb(172, 57, 255);"><span style="letter-spacing: 2px;"><strong>Thunderdome白皮书</strong><strong>请</strong></span><strong style="letter-spacing: 2px;">求</strong></span><span style="letter-spacing: 2px;">《<strong>Request for White Paper DISA-OTA-21-9-Thunderdome</strong>》，并且更新了<strong>7个版本</strong>。如下图所示：</span></section><section style="margin-top: 15px;white-space: normal;"><span style="letter-spacing: 2px;"></span></section><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-fileid="100010837" data-galleryid="" data-ratio="0.9961612284069098" data-s="300,640" style="" data-type="png" data-w="1042" src="https://wechat2rss.xlab.app/img-proxy/?k=1efe2f67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOgg3KYFqz1B8YU6m3dAkJSjun2WNH6odokaEBpyq2XmFNl1ndcpTOZgK8TMiaDgkp24icOesu7Gmcg%2F640%3Fwx_fmt%3Dpng"/></section><p style="text-align: center;">图1-Thunderdome白皮书请求</p><section style="margin-top: 15px;white-space: normal;"><strong>Thunderdome项目本质上就是零信任/SASE原型项目</strong>。Thunderdome的提出，相当于实锤了国防部向SASE架构的演进趋势。</section><section style="margin-top: 15px;white-space: normal;">2021年1月，笔者曾在<span style="color: rgb(0, 82, 255);">《</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494017&amp;idx=1&amp;sn=cbebe869893bba17fdb798d2bb0965a0&amp;chksm=97fa34e7a08dbdf1104e434350b7c6effc6410e473c148c81435c0d423aa80a7ff1bfca3220d&amp;scene=21#wechat_redirect" textvalue="美军网络安全 | 用零信任替代中间层安全？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="color: rgb(0, 82, 255);text-decoration: underline;">美军网络安全 | 用零信任替代中间层安全？</span></a><span style="color: rgb(0, 82, 255);">》</span>一文中，说明<strong>JRSS（联合区域安全栈）</strong>是<strong style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">标准化</strong><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">的</span><span style="outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(172, 57, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">中间层安全</strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">设备。<strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">2020财年<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">DOT&amp;E</strong>年度报告<strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">，强烈地</strong><span style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;color: rgb(0, 0, 0);box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">期待零信任架构能够替代JRSS，</strong></span><span style="letter-spacing: 0.544px;"><strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">承担起国防部网络的</strong></span></strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);color: rgb(0, 0, 0);"><strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-align: left;background-color: rgb(255, 255, 255);outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">中间层安全</strong></span></strong></span><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;"><strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;">的重任</strong><span style="letter-spacing: 0.544px;">。</span></span></strong></span><br/></section><section style="margin-top: 15px;white-space: normal;"><span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);"><strong style="outline: 0px;max-width: 100%;letter-spacing: 0.544px;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="letter-spacing: 0.544px;"><span style="letter-spacing: 0.544px;"></span></span></strong></span></section><p><strong style="white-space: normal;">2021年10月</strong>，美国武装部队通信与电子协会（AFCEA）举办了<strong>2021年度TechNet Cyber会议</strong>。会上进一步明确，国防部决定逐步淘汰JRSS，并考虑<strong>将Thunderdome作为JRSS的替代方案</strong>。如果Thunderdome得到验证，DISA会将JRSS计划过渡到零信任架构。这也是本界<strong style="white-space: normal;">TechNet Cyber</strong>大会上最令人激动的事情之一。</p><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">战略定位<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><p style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-fileid="100010843" data-galleryid="" data-ratio="0.3932411674347158" data-s="300,640" style="text-align: center;white-space: normal;" data-type="png" data-w="1953" src="https://wechat2rss.xlab.app/img-proxy/?k=c12c37ba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOgg3KYFqz1B8YU6m3dAkJSYXzN4gqLdf4kycicVuNS6Kevoq9c2ZiadJB8yabmuYuMg90wvWrfadbQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-top: 15px;">图2-<span style="text-align: left;">国防部零信任实施框架</span><br/></p><p style="text-align: left;margin-top: 15px;">笔者从上面这张图中，大致推断Thunderdome的战略定位：</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>国防部的零信任，将主要由<span style="text-align: left;">企业级<strong>ICAM</strong>（身份、凭证与访问管理）和<strong>Thunderdome</strong></span>构成。<span style="color: rgb(172, 57, 255);"><strong><span style="color: rgb(172, 57, 255);text-align: left;">ICAM</span>是底层基础设施</strong>；<strong><span style="color: rgb(172, 57, 255);text-align: left;">Thunderdome</span>是上层架构</strong></span>。</p></li><li><p><strong>所有访问者</strong>，使用多因素认证（MFA）、通用访问卡（CAC）、PIV、令牌、口令等方式，通过ICAM基础设施进行认证。同时，在访问过程中，会对所有账号进行生命周期管理和审计。</p></li><li><p><strong>被访问资源</strong>，分为两大类：一是本地的资源和数据；二是云中资源和数据。</p></li><li><p><strong>访问过程的控制和分析手段</strong>：包括<strong>策略强制执行（PE）</strong>、<strong>微分段（MSG）</strong>、<strong>网空态势感知（CSA）</strong>。<br/></p></li></ul><section style="text-align: left;margin-top: 15px;"><span style="text-align: left;">再解释下：笔者</span>在写本文之前，都一直难以理解<strong style="white-space: normal;"><span style="text-align: left;">Thunderdome</span></strong><span style="text-align: left;">这个名称的内在</span>含义。直到看到这张图，才觉得<strong style="text-align: left;white-space: normal;">Thunderdome</strong>最好被拆分为两个单词——<strong style="text-align: left;white-space: normal;">Thunder dome</strong>，被翻译成<strong style="text-align: left;white-space: normal;">“雷霆<strong style="text-align: left;white-space: normal;">穹顶</strong>”</strong>比较合适，因为<strong style="text-align: left;white-space: normal;">Thunderdome</strong>在此图中的位置正是<strong>穹顶</strong>。<strong style="text-align: left;white-space: normal;"></strong></section><section style="text-align: left;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">主要意图<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;white-space: normal;"><strong>国防部正在计划在SASE安全框架内实施关键的零信任概念</strong>。这些是国防部的新作战能力，它将显著改善路由和安全服务。</section><section style="margin-top: 15px;white-space: normal;">DISA发布Thunderdome白皮书请求（RWP）的主要目的，就是着眼于零信任实施相关的<strong>原型、开发、测试</strong>活动。DISA计划<strong>采购</strong>工具/系统/能力，以在国防部的<strong>SIPRNet</strong>（机密互联网协议路由器网络）和<strong>NIPRNet</strong>（非机密IP路由器网络）上，部署具有<strong>SASE能力、集成SD-WAN技术、客户边缘安全栈、应用程序安全栈</strong>的<strong>零信任安全模</strong><strong>型</strong>。 </section><section style="margin-top: 15px;white-space: normal;">国防部打算通过实施本项目，充分利用<strong>商业最佳实践</strong>，建立若干工具和流程的<span style="color: rgb(172, 57, 255);"><strong>原型</strong></span>。具体而言，国防部打算创建、设计、开发、演示以下安全能力的运行效用：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>SASE</strong>；</p></li><li><p>DISN（国防信息系统网络）客户边缘PoP（存在点）的<strong>客户边缘安全栈</strong>；</p></li><li><p>部署在应用程序工作负载前的可扩展<strong>应用程序安全栈</strong>。</p></li></ul><section style="margin-top: 15px;white-space: normal;"><strong>SD-WAN集成</strong>包括提供<strong>微分段</strong>和特定<strong>流量优先级排序</strong>的能力。这些能力将与现有DISA系统（如ICAM、遵从连接（C2C）、端点系统、SIEM、数据分析平台等）集成，提供条件化访问和策略，<strong>基于用户和端点属性</strong>以及<strong>基于应用程序和数据标签的策略</strong>，来限制访问功能。</section><section style="text-align: left;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">技术关注度<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><span style="color: rgb(25, 25, 24);font-family: Lato, sans-serif;text-align: start;background-color: rgb(255, 255, 255);font-size: 17px;">DISA新任命的<strong>首席技术官（CTO）</strong>兼<strong>新兴技术办公室负责人</strong>Steve Wallace，在2021年10月Forecast to Industry（行业预测） 2021的演讲PPT中，主要展示了下面这张图：</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-fileid="100010844" data-galleryid="" data-ratio="0.4774436090225564" data-s="300,640" style="" data-type="png" data-w="1862" src="https://wechat2rss.xlab.app/img-proxy/?k=e901cf32&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPOgg3KYFqz1B8YU6m3dAkJS2rshCn9nde160r1VLFgnYTY6Dxz9LoeeOHeUOOG7Wiblcyf5Ljgia7WQ%2F640%3Fwx_fmt%3Dpng"/><br/></p><p style="text-align: center;">图3-2022财年DISA技术观察名单</p><section style="text-align: left;margin-top: 15px;">从上图中，笔者观察到：<br/></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>所有被关注技术的热度/成熟度</strong>：自内向外依次降低，共分为<strong>4个环</strong>：第1环是部署环（Deploy）；<span style="text-align: left;">第2环是原型环（Prototype）；第3环是计划环（Plan）；第4环是监视环（Monitor）。</span></p></li><li><p><strong><span style="text-align: left;">第1环（部署<span style="text-align: left;">）</span></span></strong><span style="text-align: left;">：包括<strong>CAIM（网络资产清单管理）</strong>、BYOAD（自带批准设备）、企业灰核（Enterprise Grey Core）；</span></p></li><li><p><span style="text-align: left;"><strong style="white-space: normal;">第2环（原型）</strong>：包括<strong style="white-space: normal;"><span style="text-align: left;">Thunderdome</span></strong>、<strong>ICAM</strong>（身份、凭证和访问管理）、<strong>AI/ML</strong>（人工智能/机器学习）、<strong>SOAR</strong>（安全编排、自动化和响应）、自动化（Automation）、移动/桌面融合、<strong>涉密移动能力</strong>；</span></p></li><li><p><strong><span style="text-align: left;">第3环（计划）</span></strong><span style="text-align: left;">：<span style="text-align: left;">包括<strong style="white-space: normal;">零信任</strong>（Zero Trust）、边缘计算、<strong>入侵与攻击模拟</strong>（BAS，Breach and Attack Simulation）、分布式账本（Distributed Ledgers）、<span style="color: rgb(25, 25, 24);font-family: Lato, sans-serif;font-size: 18px;text-align: start;background-color: rgb(255, 255, 255);">反向浏览器隔离</span>等；</span></span></p></li><li><p><strong><span style="text-align: left;">第4环（监视）</span></strong>：包括<strong>加密流量分析</strong>（Encrypted Traffic Analysis）等；<br/></p></li></ul><section style="margin-top: 15px;">可以看出，<strong><span style="text-align: left;">Thunderdome</span></strong>处于<strong>第2环（原型）</strong>，而<strong>零信任</strong>（Zero Trust）处于<strong>第3环（计划）</strong>。由于<span style="text-align: left;">Thunderdome</span>是零信任的一个具体实现方案，所以对<span style="text-align: left;">Thunderdome</span>的紧迫性更高。<span style="color: rgb(25, 25, 24);font-family: Lato, sans-serif;font-size: 18px;letter-spacing: 2px;text-align: start;background-color: rgb(255, 255, 255);">Steve Wallace说：“<strong>能力的好坏取决于它的实施</strong>。”因此，<strong>国防部零信任能力的好坏，取决于<strong style="white-space: normal;"><span style="text-align: left;">Thunderdome</span></strong>的实施</strong>。</span></section><section style="text-align: left;margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">技术要求<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="margin-top: 15px;">在第7版<span style="text-align: left;">Thunderdome</span>白皮书请求（<span style="text-align: left;">RWP</span>）中，给出了<strong>评估供应商技术优势</strong>的<strong>标准</strong>：</section><section style="margin-top: 15px;">A.供应商创建、设计、开发、集成<span style="color: rgb(172, 57, 255);"><strong>SASE</strong></span>的方法；<br/></section><section style="margin-top: 15px;">B.供应商实施可由<strong>DISA作为服务提供商</strong>管理的<strong>SASE能力</strong>的方法；</section><section style="margin-top: 15px;">C.供应商实现支持<strong>多租户</strong>（多个客户和组织）的<strong>SASE能</strong>力的方法；</section><section style="margin-top: 15px;">D.供应商提供可部署到<strong>本地客户位置</strong>或<strong>云托管企业位置</strong>的拟议SASE解决方案的技术方法；</section><section style="margin-top: 15px;">E.供应商在DISN <strong>POP</strong>创建、设计、开发、集成<span style="color: rgb(172, 57, 255);"><strong>客户边缘安全栈</strong></span>的方法；</section><section style="margin-top: 15px;">F.供应商在<strong>应用程序工作负载</strong>前创建、设计、开发、集成可扩展<span style="color: rgb(172, 57, 255);"><strong>应用程序安全栈</strong>的</span>方法和创新；</section><section style="margin-top: 15px;">G.供应商设计、开发、集成用于防御性网络作战（DCO）和持续监控的<span style="color: rgb(172, 57, 255);"><strong>网络态势感知</strong></span><strong>（SA）</strong>工具的方法；</section><section style="margin-top: 15px;">H.供应商获取、丰富、格式化、转换<strong>数据</strong>的方法；</section><section style="margin-top: 15px;">I.供应商的<strong>数据持久化</strong>方法（90天热存储、180天热存储、365天冷存储）；</section><section style="margin-top: 15px;">J.供应商查询、共享、可视化<strong style="white-space: normal;">网络态势感知</strong>数据的方法；</section><section style="margin-top: 15px;">K.供应商开发<strong style="white-space: normal;">网络态势感知</strong>解决方案的方法，该解决方案在给定环境的情况下尽可能具有可移植性和云不可知性；</section><section style="margin-top: 15px;">L.供应商采用<strong>标准化身份</strong>来验证用户和设备的方法；</section><section style="margin-top: 15px;">M.供应商制定新的基于风险的安全策略以促进<strong>条件访问</strong>的方法；</section><section style="margin-top: 15px;">N.供应商将<strong>访问策</strong>略与<strong>用户属性</strong>和<strong>设备加固状态</strong>相关联的方法；</section><section style="margin-top: 15px;">O.供应商集成<strong>端点技术</strong>的方法；</section><section style="margin-top: 15px;">P.供应商实现<strong>多种设备</strong>和<strong>来自不同地点</strong>的<strong>条件访问</strong>的方法；</section><section style="margin-top: 15px;">Q.供应商从任何设备上的任何位置提供<strong>一致体验</strong>的方法，可针对用户设备进行优化；</section><section style="margin-top: 15px;">R.供应商以连续、一致、低延迟的方式提供<strong>遥测</strong>（日志/事件数据）的方法；</section><section style="margin-top: 15px;"><span style="text-decoration: line-through;">S.供应商与<strong>安全DNS架构</strong>集成的方法；</span></section><section style="margin-top: 15px;">T.供应商保护国防部免受<strong>DDoS</strong>（分布式拒绝服务攻击）的方法；</section><section style="margin-top: 15px;">U.供应商确保DISA能够支持在NIPR和SIPR连接上从SD-WAN控制器到DISN主干的默认（静态路由）或BGP（边界网关协议）对等的方法；</section><section style="margin-top: 15px;">V.供应商为<strong>租户客户</strong>提供服务门户的方法，提供服务状态和SLA指标，以及租户管理员管理特定于租户的网络和安全服务策略和配置的能力；</section><section style="margin-top: 15px;">W.供应商<span style="color: rgb(0, 0, 0);"><strong>自动化和编排</strong></span>网络和安全服务的设计和部署的方法，包括软件增强、更新和补丁的敏捷部署；</section><section style="margin-top: 15px;">X.供应商提供<strong>设备清单、软件清单、配置、配置合规性、漏洞状态</strong>的方法，包括<strong>端点保护</strong>工具和功能的配置；</section><section style="margin-top: 15px;">Y.供应商创建、设计、开发、集成SD-WAN的方法和创新，包括提供<strong>微分段、自动资源调配、流量优先级排序</strong>；</section><section style="margin-top: 15px;">Z.供应商支持用户指定边界的<span style="color: rgb(172, 57, 255);"><strong>SD-WAN方法</strong></span>，不受设施、地理、设备和作战人员移动和位置的限制：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p>aa.供应商<strong>使用现有宽带能力的SD-WAN方法</strong>——无MPLS（多协议标签交换）/VLAN（虚拟局域网）；</p></li><li><p>bb.供应商在<strong>处理之前</strong><strong>对网络流进行身份验证</strong>的方法；</p></li><li><p>cc.供应商在<strong>传输之前</strong><strong>加密网络流</strong>的方法；</p></li><li><p>dd.供应商的<strong>混合网络SD-WAN方法</strong>，其中一些流量在SD-WAN上，而其他流量在MPLS和OOT操作上；</p></li><li><p>ee.当SLA降至用户指定级别以下时，供应商提供<strong>网络和网络路径按需可扩展</strong>的方法；</p></li><li><p>ff.供应商监控SD-WAN并在细粒度级别提供<strong>网络流量可见性</strong>的方法；</p></li><li><p>gg.供应商在<strong>4个NIPR站点</strong>（DISA HQ、DISA PAC、DISA EUR、JSP）实施完整解决方案的方法，<strong>每个站点估计有5000名用户</strong>；</p></li><li><p>gg.供应商测试和实施<strong>完整Thunderdome原型</strong>的方法，应通过<strong>里程碑图</strong>进行描述，且需在授予之日起的<strong style="white-space: normal;">6个月内完成</strong>。</p></li></ul><section style="margin-top: 15px;">从上面罗列的技术要求，大致可以看出，<span style="text-align: left;">Thunderdome</span>项目主要涉及<strong style="white-space: normal;">SASE、<strong style="white-space: normal;">SD-WAN</strong>、<strong style="white-space: normal;"><strong>网络态势感知</strong>、</strong><strong style="white-space: normal;">客户边缘安全栈、<strong style="white-space: normal;">应用程序安全栈</strong>、条件访问、自动化编排、资产/配置/漏洞、<strong style="white-space: normal;">微分段、流量优先级排序</strong></strong></strong>等。<strong style="white-space: normal;"><strong style="white-space: normal;"><strong style="white-space: normal;"></strong></strong></strong><br/></section><section style="margin-top: 15px;"><span style="text-align: center;">下图展示了部分关键技术与</span><span style="text-align: center;">国防部零信任</span><span style="text-align: center;">七支柱</span><span style="text-align: center;">之关系：</span></section><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-fileid="100010847" data-galleryid="" data-ratio="0.4298780487804878" data-s="300,640" style="" data-type="png" data-w="1968" src="https://wechat2rss.xlab.app/img-proxy/?k=5717d956&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPffBZP7LzpdQGfJFru6LSoUYYunVkMMfq5nOOJq8gVlKUMWU67jSeBqGlQln2kbOodhQPLH4ia77Q%2F640%3Fwx_fmt%3Dpng"/></section><p style="text-align: center;">图4-关键技术与国防部零信任七支柱之关系</p><section style="text-align: left;margin-top: 15px;">以笔者的观点看：为了覆盖<span style="text-align: center;">国防部零信任的七大支</span><span style="text-align: center;">柱</span>，上图左边罗列的关键技术都是必不可少的，因此可以视为<strong>零信任实施的最小集</strong>。<br/></section><p style="margin-top: 15px;"><br/></p><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">实施计划<br/></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;margin-bottom: 10px;white-space: normal;letter-spacing: 2px;background: white;font-family: PingFangSC-light;font-size: 16px;text-align: left;line-height: 1.5em;"><br/></section><section style="text-align: left;margin-top: 15px;">如果您在过去 20 年里一直关注DISA，有一件事很清楚：<span style="text-align: left;">DISA</span>确实喜欢<strong>试点</strong>或<strong>概念验证</strong>（POC）。</section><section style="text-align: left;margin-top: 15px;">而DISA正是<strong>将Thunderdome作为零信任的原型</strong>，以验证构成零信任架构的概念。从一定程度上看，<strong>Thunderdome</strong><strong>试点将</strong><strong>是对国防部信息网络的</strong><span style="color: rgb(172, 57, 255);"><strong>彻底重构</strong></span>。这项试点活动将帮助国防部理解<strong>如何在整个国防部实施这一计划</strong>。</section><section style="text-align: left;margin-top: 15px;">在Thunderdome白皮书请求（RFW）的各种版本中，给出了<strong>里程牌</strong>计划。</section><section style="text-align: left;margin-top: 15px;"><strong>第5版</strong>中的<strong>里程牌</strong>，如下图所示：</section><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-backh="430" data-backw="578" data-fileid="100010845" data-galleryid="" data-ratio="0.7441002949852508" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1356" src="https://wechat2rss.xlab.app/img-proxy/?k=2e67813e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPffBZP7LzpdQGfJFru6LSoRrh9v1A19BKY2x9CPdfFyK8fd6Vm9VImgTjkefNKPn2v8ichIcpzLhg%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;margin-top: 15px;"><span style="text-align: left;">图5-Thunderdome里程碑（第5版<span style="text-align: left;">）</span></span></section><p style="text-align: left;margin-top: 15px;">但是，在<strong>第6版和第7版中，</strong><strong>却</strong><strong>删除了里程碑</strong>。如下所示：</p><section style="text-align: center;margin-top: 15px;"><img class="rich_pages wxw-img" data-fileid="100010846" data-galleryid="" data-ratio="0.7611420612813371" data-s="300,640" style="" data-type="png" data-w="1436" src="https://wechat2rss.xlab.app/img-proxy/?k=1023763b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPffBZP7LzpdQGfJFru6LSoH03qhZ4q0BiaUvMHm0iapCsfMchxyIljuDEUrIKqlvn4XmK41hgJm6Yw%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 15px;white-space: normal;text-align: center;"><span style="text-align: left;">图6-Thunderdome里程碑被删除（第7版）</span></section><section style="margin-top: 15px;">尽管最新版中删除了<span style="text-align: left;">里程碑图</span>，<span style="text-align: left;">但也要求白皮书提交者必须提交里程碑图。笔者推测：也许是DISA不想对供应商的时间进度控制得过度苛刻，而是多给他们一些灵活空间。</span></section><section style="margin-top: 15px;"><span style="text-align: left;">但是，<strong>白皮书<strong style="text-align: left;white-space: normal;">请求</strong>中的<span style="text-align: left;">里程碑</span>，多少反映了DISA对Thunderdome的进度期待</strong>。从中可以看出：</span></section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><span style="text-align: left;">里程碑划分成<strong>3个阶段</strong>（Phase），共计19个里程碑节点；</span></p></li><li><p><span style="text-align: left;">每个阶段<span style="text-align: left;">（Phase）</span>大概2个月，3个阶段<strong>总</strong><strong>共</strong><strong>半年时间</strong>；</span></p></li></ul><section style="text-align: left;margin-top: 15px;"><span style="text-align: left;">Thunderdome白皮书请求（RFW）的截止日期是<strong>2021年9月</strong>3日</span>。当前，DISA正在<strong>审查</strong>各个供应商提交的<strong style="text-align: left;white-space: normal;">Thunderdome</strong><strong>白皮书</strong>，计划采用三阶段评估方法，授予Thunderdome原型：</section><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p><strong>第一阶段-白皮书评估</strong>：按照评估标准，针对收到的白皮书进行评估，以确定最小可行产品（MVP）。</p></li><li><p><strong>第二阶段-口头陈述</strong>：邀请第一阶段选定的供应商提供口头陈述，可通过视频会议或电话进行。在演示过程中，供应商应准备详细讨论其解决方案。</p></li><li><p><strong>第三阶段-项目建议书申请</strong>：向第二阶段中<strong>不超过两个供应商</strong>，发出项目建议书请求（RFPP）。</p></li></ul><section style="text-align: left;margin-top: 15px;">除了<span style="text-align: left;">Thunderdome计划本身，<strong>ICAM</strong>也是DISA零信任实施的关注重点。</span>多年来国防部一直在本地运行PKI，DISA希望利用其传统PKI，<strong style="text-align: justify;">在混合云环境中实现PKI现代化</strong><span style="text-align: justify;">。DISA预计将在2022财年第二季度发布PKI现代化支持服务的<strong>提案请求</strong>，并在2023财年做出授予。作为</span><strong style="text-align: justify;">PKI现代化</strong><span style="text-align: justify;">的一部分，DISA新任首席技术官 Steve Wallace 表示，</span>DISA将继续寻找新方法，来<span style="color: rgb(172, 57, 255);"><strong style="text-align: justify;">简化身份和访问管理</strong></span><span style="text-align: justify;">，同时又不失安全性。</span></section><section style="text-align: left;margin-top: 15px;"><span style="text-align: justify;"></span></section><section style="text-align: left;margin-top: 15px;"><span style="text-align: justify;"></span></section><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span><span style="text-align: center;"></span></section>



<p><a href="2247494496">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=768793e0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494496%26idx%3D1%26sn%3D4898d7237fecce4e148941978a13be6d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 07 Nov 2021 08:53:00 +0800</pubDate>
    </item>
    <item>
      <title>《美国联邦政府零信任战略》</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzIxNzUxNzA2NQ==&amp;mid=2247494482&amp;idx=1&amp;sn=6846eec033fe7d04d70b0a5d68105b75</link>
      <description>零信任不会不来，只会迟到。</description>
      <content:encoded><![CDATA[<p>
原创 <span>柯善学</span> <span>2021-09-09 07:44</span> <span style="display: inline-block;"></span>
</p>

<p>零信任不会不来，只会迟到。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dc8a8f27&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2F4EtGnz3lAPPia8hCJibl8gQVXOSrjibbmuc3K7ibwee6ibuYHgxlDmedat2zj0Z4fE8HzjAFAWP93JNlWib8iaxcXPrDA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="white-space: normal;text-align: left;">全文约<strong>50</strong><span style="color: rgb(0, 0, 0);"><strong>00</strong></span>字  阅读约<span style="color:#000000;"><strong>15</strong></span>分钟</p><section style="white-space: normal;max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;overflow-wrap: break-word !important;"><section style="padding-right: 20px;padding-left: 20px;max-width: 100%;box-sizing: border-box;line-height: 0.8;overflow-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;text-align: center;overflow-wrap: break-word !important;"><br/></p></section></section></section></section><section data-mpa-template="t" mpa-from-tpl="t" style="white-space: normal;max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="margin: 5px;max-width: 100%;text-align: center;border-width: 1px;border-style: solid;border-color: rgb(7, 0, 144);box-shadow: rgb(136, 136, 136) 0px 0px 10px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="padding: 10px;max-width: 100%;line-height: 28px;overflow-wrap: break-word !important;box-sizing: border-box !important;"><section mpa-from-tpl="t" style="max-width: 100%;overflow-wrap: break-word !important;box-sizing: border-box !important;"><p style="text-align: left;margin-top: 10px;">这无疑是目前<strong>零信任应用领域</strong>的最大消息——表明整个美国联邦政府已经正式开启零信任战略。</p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;">美国</span><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">管理和预算办公室（OMB）在</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">2021年9月7日</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布了《</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">联邦零信任战略》（Federal Zero Trust Strategy）草案</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">，以支持</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">第<strong style="outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">14028</strong>号</strong><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">行政指令</strong><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">（EO 14028）《改善国家网络安全》</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">，以改变</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">民用机构</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">的</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">企业安全架构</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">，使其</span><strong style="font-size: 16px;outline: 0px;max-width: 100%;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;">基于零信任原则</strong><span style="font-size: 16px;font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;">拜登总统曾在EO 14028中指出：</span><span style="font-size: 16px;">“</span><strong style="font-size: 16px;">渐进式改进</strong><span style="font-size: 16px;">不会为我们提供所需的安全性；</span><span style="font-size: 16px;">相反，</span><strong style="font-size: 16px;">联邦政府需要做出<span style="color: rgb(172, 57, 255);">大胆的改变</span>和<span style="color: rgb(172, 57, 255);">重大的投资</span></strong><span style="font-size: 16px;">，以保护支撑美国生活方式的重要机构。</span><span style="font-size: 16px;">” 而本次的《联邦政府零信任战略》无疑就是对此的最好支持和回应。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;"><strong><span style="text-align: left;"><strong style="font-size: 16px;text-align: left;white-space: normal;">《联邦政府零信任战略》</strong>的目的是将政府机构的企业安全架构迁移到零信任架构。但该战略文件</span>只是一个</strong></span><span style="font-size: 16px;color: rgb(172, 57, 255);"><strong>起点</strong></span><span style="font-size: 16px;"><strong>，而不是完全成熟的零信任架构的综合指南</strong>。当然，<strong>零信任的成熟度模型和参考架构</strong>，已经在该战略的参考文献中列出，政府机构应该使用它们来规划和执行其长期安全架构的迁移计划。</span></p><p style="text-align: left;margin-top: 10px;"><span style="font-size: 16px;">本战略草案的PDF文档有23页，译文大概<strong>1万5千字</strong>。笔者概述了本战略的<strong>内容要点</strong>，并做了<strong>相关解读</strong>。战略草案原文链接：<a href="https://zerotrust.cyber.gov/federal-zero-trust-strategy/" target="_blank">https://zerotrust.cyber.gov/federal-zero-trust-strategy/</a></span></p></section></section></section></section></section><section style="margin-top: 15px;"><strong><span style="text-align: left;">关键词</span></strong><span style="text-align: left;">：《联邦政府零信任战略》（Federal Zero Trust Strategy）；<strong><span style="text-align: left;">OMB</span></strong>（<span style="text-align: left;">管理和预算办公室</span>）；<strong>EO 14028</strong>（第<span style="text-align: left;">14028</span>号行政指令，Executive Order 14028）《改善国家网络安全》；MFA（多因素认证）；<span style="font-family: -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">CISA (网络安全和基础设施安全局)</span>；GSA（总务管理局）</span></section><section style="text-align: center;margin-top: 15px;"><span style="font-size: 20px;"><strong>目  录</strong></span><br/></section><section style="margin-top: 15px;">1.战略背景解读<br/>2.战略路径解读</section><p>3.支柱目标1：身份</p><p>4.支柱目标2：设备</p><p>5.支柱目标3：网络</p><p>6.支柱目标4：应用</p><p>7.支柱目标5：数据</p><p>8.本战略的参考文件</p><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">01</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">战略背景解读</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><section style="margin-top: 15px;"><br/></section><section style="margin-top: 15px;">《<strong style="white-space: normal;">联邦政府零信任战略》（Federal Zero Trust Strategy）草案</strong>发布的网站截图如下：<strong style="white-space: normal;"></strong></section><section style="margin-top: 15px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6062416998671979" data-s="300,640" style="text-align: center;white-space: normal;" data-type="png" data-w="1506" src="https://wechat2rss.xlab.app/img-proxy/?k=fe432b77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPia8hCJibl8gQVXOSrjibbmuckH1OTP2uZibpTd9vOeQomspG2GXZgT8QtxlylV9GmqI6rnBoOz0j71Q%2F640%3Fwx_fmt%3Dpng"/></section><p style="margin-top: 15px;">本战略文档开宗明义：“管理和预算办公室（OMB）在<strong>2021年9月7日</strong>发布了《<strong>联邦政府零信任战略》草案</strong>，以支持<strong>第<strong style="white-space: normal;">14028</strong>号</strong><strong>行政指令</strong><strong>（EO 14028）《改善国家网络安全》</strong>，以改变<strong>民用机构</strong>（civilian agencies）的<strong>企业安全架构</strong>，使其<strong>基于零信任原则</strong>。”<br/></p><p style="margin-top: 15px;">笔者对上面这段文字，给予解读：<br/></p><p style="margin-top: 15px;"><strong>1）</strong><strong>零信任战略是用来支撑EO 14028的</strong>。该战略中也重申了EO 14028的重要性：“成功地使<strong style="white-space: normal;">联邦政府的安全方法现代化，需要全政府的努力</strong>。2021 年 5 月，总统发布了第14028号行政指令 (EO)，《改善国家网络安全》，启动了<strong>政府范围内的全面努力</strong>，以确保基线安全实践到位，<span style="color: rgb(172, 57, 255);"><strong>将联邦政府迁移到零信任架构</strong></span>，并实现基于云的基础架构的安全优势，同时降低相关风险。”很明显，EO 14028中已经对联邦政府向零信任架构的迁移做出了明确指示。而这次发布的<strong>《<strong style="white-space: normal;">联邦零信任战略》</strong></strong>就是进一步明确联邦政府零信任战略的实施。</p><p style="margin-top: 15px;">2）战略中最重要的关键词无疑是“<strong>机构</strong>”（agencies）。简单理解，主要是指<strong>政府机构</strong>。那为什么要强调“<strong style="white-space: normal;">民用机构</strong>”（civilian agencies）呢？这主要是和美国国防部这类的“<strong>军用机构</strong>”划分界限。我们可以简单将本战略中的“<strong style="white-space: normal;">民用机构</strong>”理解为“<strong>政府机构</strong>”。<br/></p><p style="margin-top: 15px;"><strong>3）为什么要保护这些政府机构？</strong>该战略中提到：“<strong style="white-space: normal;"></strong>每天，<strong>联邦政府</strong>都在执行独特且极具挑战性的任务：<strong>机构</strong>保护我们国家的关键基础设施、开展科学研究、参与外交、为美国人民提供福利和服务，以及许多其他公共职能。为了有效地执行这些任务，我们的国家必须明智而积极地利用现代技术和安全实践，同时避免恶意网络活动造成的破坏。”<br/></p><p style="margin-top: 15px;"><strong>4）零信任战略的目的是将政府机构的企业安全架构迁移到零信任架构</strong>。这里面的“<strong>企业安全架构</strong>”就不多解释了。在美国人眼中，<strong>一切机构皆为“企业”</strong>，不论民用机构还是军用机构。比如，美国国防部，就是最典型的“企业”。</p><p style="margin-top: 15px;"><strong>5）</strong><strong style="white-space: normal;">评论期很短，正式版可能很快发布。</strong>注意到，该战略草案的<strong>评论期只有两周（<strong>2021年9月21日</strong>之前）</strong>，时间很短。说明OMB希望尽快发布正式版。</p><p style="margin-top: 15px;">6）<strong style="white-space: normal;">美国国防部</strong>是美国联邦政府机构的零信任先锋。美国机构虽然有军用和民用之分，但不要轻视美国国防部对美国联邦政府的影响力。美国国防部曾经称自己不是一个“热衷于追求热词”的部门。但在零信任这个方向上，国防部如此激进，甚至走在所有联邦政府机构的前头，就是因为美国国防部提前认识到零信任的价值。而现在整个联邦政府都全面转向零信任架构，不能不说：美国国防部功不可没。笔者当然是深知美国国防部的影响力，所以才会在美国国防部开始重视零信任的早期，就密切关注零信任形势的发展。</p><p style="margin-top: 15px;">7）尽管零信任背后的概念并不新鲜，但<strong>对联邦机构而言仍然是一个</strong><span style="color: rgb(172, 57, 255);"><strong>重大转变</strong></span>，因为从概念上<strong>消除了对设备和网络的隐式信任</strong>。这要求美国政府机构的安全架构必须假设——网络和其他组件将受到入侵和损害，并且要求遵循<strong>最小权限原则</strong>。</p><p style="margin-top: 15px;"><strong>8）联邦政府<strong style="white-space: normal;">零信任战略</strong>是一项大胆的行动</strong>。对于像联邦政府这样复杂且技术多样的<strong>企业</strong>来说，过渡到零信任架构不是一项容易的任务。但正如拜登总统在 EO 14028 中所述，“<span style="color: rgb(172, 57, 255);"><strong>渐进式改进</strong></span><strong>（Incremental improvements）不会为我们提供所需的安全性；相反，联邦政府需要做出</strong><span style="color: rgb(172, 57, 255);"><strong>大胆的改变</strong></span><strong>（bold changes）和</strong><span style="color: rgb(172, 57, 255);"><strong>重大的投资</strong></span><strong>（significant investments）</strong>，以保护支撑美国生活方式的重要机构。”</p><p style="margin-top: 15px;"><strong>9）零信任战略实施进展时间要求</strong>：</p><ul class="list-paddingleft-2" style="list-style-type: disc;"><li><p style="margin-top: 15px;">该战略要求政府机构在<strong>2024 财年</strong> (FY) 结束前，实现特定的零信任安全目标（具体目标参加下文中的<strong>五个支柱</strong>）。</p></li><li><p>EO 14028要求各机构制定自己的零信任架构实施计划。在本战略发布之日起 60 天内，各部门和机构应在各自零信任架构实施计划的基础上，<strong>纳入本战略中规定的额外要求</strong>，并向 OMB 提交 22-24 财年的实施计划和 23-24 财年的预算估算。<strong>机构应在22财年重新确定资金的优先次序</strong>，以实现优先目标，或从其他来源寻求资金。</p></li><li><p>自本战略发布之日起，部门和机构将有 30 天的时间，为其组织指定和确定<strong>零信任架构实施负责人</strong>。OMB将依靠这些指定的领导，进行政府范围内的协调以及参与每个组织内的规划和实施工作。</p></li></ul><section style="margin-top: 15px;white-space: normal;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">02</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">战略路径解读</strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）联邦<strong>零信任战略</strong>不是什么？零信任战略并不试图描述或规定一个完全成熟的零信任实现</strong>。甚至不鼓励任何机构超越此战略中所述的行动。该战略的目的是通过<strong>制定机构必须采取的</strong><span style="color: rgb(172, 57, 255);"><strong>初始步骤</strong></span>，将所有联邦机构置于一个<strong>共同路线图</strong>上，以使其迈向通往高度成熟的零信任架构的<strong>旅程</strong>。它承认每个机构目前处于不同的成熟状态。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>2）联邦<strong style="white-space: normal;">零信任战略</strong>是什么？</strong><strong>零信任战略的目标是加速各机构实现早期零信任成熟度的</strong><span style="color: rgb(172, 57, 255);"><strong>共享基线</strong></span>。对于政府机构来说，<strong>转向零信任架构将是一个多年的旅程</strong>。 “EO 14028 指示机构专注于满足整个政府的<strong>关键基线安全措施</strong>，例如通用日志记录、多因素身份验证 (MFA)、可靠的资产清单、无处不在的加密使用，并采用零信任架构。” 该战略试图<strong>将机构引导到零信任架构道路上的</strong><span style="color: rgb(172, 57, 255);"><strong>最高价值起点</strong></span>，并描述了应优先考虑的几种共享服务。简单地说，联邦零信任战略是将政府机构引导到零信任的正确道路上，而且只是开了个头。</section><section style="margin-top: 15px;white-space: normal;"><strong>3）</strong>联邦零信任战略设想了一个<span style="color: rgb(172, 57, 255);"><strong>联邦零信任架构</strong></span>：</section><ul type="disc" class="list-paddingleft-2" style="width: 577.417px;white-space: normal;"><li><section style="margin-top: 15px;">支持跨联邦机构的强大<strong>身份</strong>实践；</section></li><li><section style="margin-top: 15px;">依赖<strong>加密</strong>和<strong>应用程序</strong>测试，而非边界安全；</section></li><li><section style="margin-top: 15px;"><strong>识别</strong>政府拥有的每一个设备和资源；</section></li><li><section style="margin-top: 15px;">支持安全行动的智能<strong>自动化</strong>；</section></li><li><section style="margin-top: 15px;">支持安全、稳健地使用<strong>云服务</strong>。</section></li></ul><section style="margin-top: 15px;"><strong>4）零信任战略要达成的零信任目标分为</strong><span style="color: rgb(172, 57, 255);"><strong>五个支柱</strong></span>：（分组依据是CISA (网络安全和基础设施安全局)<span style="color: rgb(172, 57, 255);"><strong>零信任成熟度模型</strong></span>的<span style="color: rgb(0, 0, 0);"><strong>五个支柱</strong></span>）</section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;"><strong>身份</strong>：机构工作人员使用<strong>企业范围的身份</strong>，来访问他们在工作中使用的应用程序。<strong>防网络钓鱼MFA</strong>，可保护这些人员免受复杂的在线攻击。</section></li><li><section style="margin-top: 15px;"><strong>设备</strong>：联邦政府拥有其运营和授权供政府使用的<strong>每台设备的完整清单</strong>，并且可以检测和响应这些设备上的事件。</section></li><li><section style="margin-top: 15px;"><strong>网络</strong>：机构在其环境中<strong>加密所有DNS请求和HTTP流量</strong>，并开始<strong>围绕其应用程序对网络进行分段</strong>。联邦政府确定了对传输中的<strong>电子邮件进行加密</strong>的可行途径。</section></li><li><section style="margin-top: 15px;"><strong>应用程序</strong>：机构将所有应用程序<strong>视为连接到互联网</strong>的应用程序，定期对其应用程序进行严格测试，并欢迎外部漏洞报告。</section></li><li><section style="margin-top: 15px;"><strong>数据</strong>：机构在部署利用<strong>彻底数据分类</strong>的保护方面有一条清晰、共享的路径。机构正在利用云安全服务来监控对其敏感数据的访问，并实施了企业范围的日志记录和信息共享。</section></li></ol><section style="margin-top: 15px;"><strong>为什么美国国防部的零信任架构是七大支柱，而联邦政府却是五大支柱？</strong>本质上，两者是一致的。看似消失的两个支柱——<strong>可见性和分析、自动化和编排</strong>，实际上是两类<strong>横切系统</strong>（在下图的底座中），贯穿到五大支柱（<strong>纵向系统</strong>）中。</section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7386569872958257" data-s="300,640" style="" data-type="png" data-w="1102" src="https://wechat2rss.xlab.app/img-proxy/?k=c5d03315&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2F4EtGnz3lAPPia8hCJibl8gQVXOSrjibbmuc2nneEWlIdUia68UdVOSfQiaajzIZM0K6YibR9mzzSZicjibco6PIgahGwNg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;">零信任的基础：五大支柱和三大基座<br/></p><section style="margin-top: 15px;">5）《<strong>美国国防部零信任参考架构》</strong>仍是联邦政府零信任架构的重要参考。该战略确实完整引用了《<strong>美国国防部零信任参考架构》</strong>中的零信任原则，不再赘述。<br/></section><section style="margin-top: 15px;white-space: normal;"><strong>6）<strong>联邦零信任战略</strong>的相关干系人</strong>。机构的首席财务官、首席采购官、机构领导层的其他人员，需要与其IT和安全领导层合作，以构建<strong>运营模型</strong>（operational model）来部署和维持零信任能力。</section><section style="margin-top: 15px;white-space: normal;"><strong>7）<strong>联邦零信任战略</strong>非常推崇对云的使用</strong>。该战略鼓励机构利用云基础设施中丰富的安全功能，该战略也多处引用云服务。</section><section style="margin-top: 15px;white-space: normal;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">8）五大支柱目标的分解行动，</strong></span></strong></span></strong></strong></strong></strong>如后文所述。</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">03</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">支柱目标1：身份</strong></span></strong></span></strong></strong></strong></strong></span><strong style="text-align: left;"></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）愿景<br/></strong></section><section style="margin-top: 15px;">机构工作人员使用<strong>企业范围</strong>的身份，来访问他们在工作中使用的应用程序。防网络钓鱼MFA可保护这些人员免受复杂的在线攻击。</section><section style="margin-top: 15px;"><strong>2）行动</strong></section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;">机构必须为机构用户建立<strong>单点登录 (SSO)</strong> 服务，该服务可以集成到应用程序和通用平台（包括云服务）中。</section></li><li><section style="margin-top: 15px;">机构必须在<strong>应用程序级别</strong>实施 MFA，并在可行的情况下使用企业 SSO。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">对于机构工作人员、承包商和合作伙伴：防钓鱼MFA是<strong>必须</strong>的。</section></li><li><section style="margin-top: 15px;">对于公共用户：防钓鱼MFA必须是一个<strong>选项</strong>。</section></li></ul><li><section style="margin-top: 15px;">机构必须采用安全的口令策略，并根据已知泄露的数据检查口令。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 将为机构提供一项或多项可以私下检查口令的服务，而不会暴露这些口令。</section></li></ul></ol><section style="margin-top: 15px;"><strong>3）关键举措</strong></section><section style="margin-top: 15px;">1. 企业范围的身份</section><section style="margin-top: 15px;">2. 多因素认证，抵御网络钓鱼</section><section style="margin-top: 15px;">3. <strong>面向公众</strong>的身份验证</section><section style="margin-top: 15px;">4. 使用强口令策略</section><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">04</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">支柱<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">目标</strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span><strong><span style="font-size: 17px;">2：设备</span></strong><strong style="text-align: left;"></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）愿景</strong></section><section style="margin-top: 15px;">联邦政府拥有它运行和授权用于政府工作的<strong>每台设备的完整清单</strong>，并且可以检测和响应这些设备上的<strong>事件</strong>。</section><section style="margin-top: 15px;"><strong>2）行动</strong></section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;">机构必须参与 CISA 的<strong>持续诊断和缓解(CDM) 计划</strong>。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 将 CDM 计划以最小特权原则为基础，并优先考虑在基于云的基础设施中的有效运行。</section></li></ul><li><section style="margin-top: 15px;">机构必须确保每个人工操作的企业配置设备，都有机构选择的<strong>端点检测和响应 (EDR) </strong>工具。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 将与机构合作，填补 EDR 覆盖范围的空白。</section></li><li><section style="margin-top: 15px;">机构必须向 CISA 提供对 EDR 数据的持续访问。</section></li></ul></ol><section style="margin-top: 15px;white-space: normal;"><strong>3）关键举措</strong></section><p><br/></p><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p>盘点资产<br/></p></li><li><p>政府范围的EDR（端点检测和响应）</p></li></ol><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">05</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">支柱<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">目标</strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span><strong><span style="font-size: 17px;">3：网络</span></strong><strong style="text-align: left;"></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）愿景</strong></section><section style="margin-top: 15px;">机构在其环境中<strong>加密所有 DNS 请求和 HTTP 流量</strong>，并开始<strong>围绕其应用程序对网络进行分段</strong>。联邦政府确定了对传输中的<strong>电子邮件进行加密</strong>的可行途径。</section><section style="margin-top: 15px;"><strong>2）行动</strong></section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;">在技术支持的任何地方，机构都必须使用加密的 DNS 来解析 DNS 查询。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 的保护性 DNS 程序，将支持加密的 DNS 请求。</section></li></ul><li><section style="margin-top: 15px;">机构必须对其环境中的<strong>所有 Web 和应用程序接口 (API) 流量，强制实施 HTTPS</strong>。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 将与机构合作，将他们的 .gov 域“预加载”到网络浏览器中，使其只能通过 HTTPS 访问。</section></li></ul><li><section style="margin-top: 15px;">CISA 将与 FedRAMP 合作，评估<strong>MTA-STS</strong>作为加密电子邮件的可行的政府范围内解决方案，并向 OMB 提出建议。</section></li><li><section style="margin-top: 15px;">机构必须与CISA 协商制定网络分段计划并将其提交给 OMB。</section></li></ol><section style="margin-top: 15px;white-space: normal;"><strong>3）关键举措</strong></section><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p>加密 DNS 流量</p></li><li><p>加密 HTTP 流量<br/></p></li><li><p>加密电子邮件流量<br/></p></li><li><p>围绕<strong>应用程序</strong><strong>分段</strong>网络</p></li></ol><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">06</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">支柱<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">目标</strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span><strong><span style="font-size: 17px;">4：应用</span></strong><strong style="text-align: left;"></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）愿景</strong></section><section style="margin-top: 15px;">机构将他们的<strong>应用程序视为连接到互联网</strong>，定期对其进行严格的实证测试，并欢迎外部漏洞报告。</section><section style="margin-top: 15px;"><strong>2）行动</strong></section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;">机构必须运行专门的应用程序安全测试程序。</section></li><li><section style="margin-top: 15px;">机构必须利用专门从事应用程序安全的高质量公司，进行独立的第三方评估。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 和 GSA 将共同努力，使此类公司可用于快速采购。</section></li></ul><li><section style="margin-top: 15px;">机构必须维持有效且受欢迎的公开漏洞披露计划。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">CISA 将提供一个漏洞披露平台，使机构系统所有者可以轻松地直接接收报告并与安全研究人员接触。</section></li></ul><li><section style="margin-top: 15px;">机构必须确定至少一个面向内部的 FISMA 中级（Moderate）应用程序，并使用企业 SSO 使其可通过公共互联网访问。</section></li><li><section style="margin-top: 15px;">CISA 和 GSA 将共同努力，为机构提供有关其在线应用程序和其他资产的数据。</section></li><ul type="circle" class="list-paddingleft-2"><li><section style="margin-top: 15px;">机构必须向 CISA 和 GSA 提供他们使用的任何非 .gov 主机名。</section></li></ul></ol><section style="margin-top: 15px;white-space: normal;"><strong>3）关键举措</strong></section><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p>应用安全测试</p></li><li><p>容易获得的第三方测试</p></li><li><p>欢迎应用漏洞报告</p></li><li><p>安全地使应用程序可访问互联网</p></li><li><p>发现可上网的应用程序</p></li></ol><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">07</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">支柱<strong style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;">目标</strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></strong></span></strong></span></strong></strong></strong></strong></span><strong><span style="font-size: 17px;">5</span></strong><strong><span style="font-size: 17px;">：数据</span></strong><strong style="text-align: left;"></strong></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;"><strong>1）愿景</strong></section><section style="margin-top: 15px;">机构在部署利用<strong>彻底数据分类</strong>的保护方面有一条清晰、共享的路径。机构利用云安全服务和工具来发现、分类和保护他们的敏感数据，并实现了企业范围的日志记录和信息共享。</section><section style="margin-top: 15px;"><strong>2）行动</strong></section><ol start="1" type="1" class="list-paddingleft-2"><li><section style="margin-top: 15px;">OMB 将与联邦首席数据官和首席信息安全官合作，制定<span style="color: rgb(172, 57, 255);"><strong>零信任数据安全策略</strong></span>和相关的实践社区。</section></li><li><section style="margin-top: 15px;">机构必须对数据分类和安全响应进行一些初始自动化，重点是<strong>标记和管理对敏感文档的访问</strong>。</section></li><li><section style="margin-top: 15px;">机构必须审计对商业云基础设施中任何<strong>静态加密数据</strong>的访问。</section></li><li><section style="margin-top: 15px;">机构必须与 CISA 合作实施全面的日志记录和信息共享功能，如OMB 备忘录 M-21-31 中所述。</section></li></ol><section style="margin-top: 15px;white-space: normal;"><strong>3）关键举措</strong></section><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p>联邦数据安全策略</p></li><li><p>自动化安全响应</p></li><li><p>审计对云中敏感数据的访问</p></li><li><p>及时获取日志</p></li></ol><section style="margin-top: 15px;"><br/></section><section data-tools="135编辑器" data-id="92984" data-color="#4f81bd" style="white-space: normal;letter-spacing: 2px;background-color: rgb(255, 255, 255);font-family: PingFangSC-light;font-size: 16px;"><section style="margin: 10px auto;display: inline-block;"><section style="border-width: 0px;border-style: none;border-color: initial;display: flex;justify-content: flex-start;align-items: flex-end;box-sizing: border-box;"><section style="width: 1.8em;text-align: center;height: 1.8em;line-height: 1.8em;font-size: 18px;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);border-radius: 100%;box-sizing: border-box;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;">08</span></section><section style="margin-bottom: 0.25em;padding-right: 5px;padding-left: 5px;max-width: 100%;display: inline-block;vertical-align: bottom;border-bottom: 1px dashed rgb(175, 175, 175);border-top-color: rgb(79, 129, 189);border-left-color: rgb(79, 129, 189);border-right-color: rgb(79, 129, 189);box-sizing: border-box;"><section data-brushtype="text" style="max-width: 100%;min-height: 1em;"><span style="font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"><strong><strong><strong><strong><span style="text-align: center;"><strong><span style="text-indent: 34px;"><strong style="text-align: left;"><strong style="white-space: normal;">本战略的参考文件</strong></strong><strong style="text-align: left;"></strong></span></strong></span></strong></strong></strong></strong></span></section></section><section style="max-width: 100%;display: inline-block;vertical-align: bottom;width: 0.5em;height: 0.5em;border-radius: 50%;background-color: rgb(79, 129, 189);color: rgb(255, 255, 255);box-sizing: border-box;"><br/></section></section></section></section><p style="margin-top: 15px;white-space: normal;"><br/></p><section style="margin-top: 15px;">本战略指出：一段时间以来，联邦政府一直在为过渡到零信任架构做准备。一些机构已经发布了对其他机构有帮助的架构模型：</section><ul type="disc" class="list-paddingleft-2"><li><section style="margin-top: 15px;"><strong>CISA 的零信任成熟度模型</strong>：是对<strong>零信任“支柱”</strong>的高级概述，展示了机构如何发展到<strong>“高级”和“最佳”状态</strong>，并描述了 CISA 服务产品如何与这些支柱保持一致。</section></li><li><section style="margin-top: 15px;"><strong>CISA 《云安全技术参考架构<strong style="white-space: normal;">》</strong></strong>：与美国数字服务部（United States Digital Service）和 FedRAMP 合作，为安全云架构和迁移策略提供了更详细的参考。</section></li><li><section style="margin-top: 15px;"><strong>NIST SP 800-207《零信任架构》指南</strong>：为零信任架构的关键原则提供了共识定义和框架，同时描述了具有不同风险状况和技能集的组织可以采用的几种不同的零信任架构方法。</section></li><li><section style="margin-top: 15px;"><strong>NIST NCCoE</strong>（国家网络安全卓越中心）已启动“<strong>实施零信任架构</strong>”计划： 与行业合作伙伴合作，将 NIST SP 800-207 中的概念应用于传统企业架构。</section></li><li><section style="margin-top: 15px;"><strong>GSA《零信任架构买家指南<strong style="white-space: normal;">》</strong></strong>：可以帮助机构确定提供与机构零信任实施相关的产品和服务的 GSA 合同工具。</section></li><li><section style="margin-top: 15px;"><strong>《国防部零信任参考架构》</strong>：全面描述了国防部计划在其系统中执行的潜在安全功能和架构控制。</section></li></ul><section><br/></section><section style="margin-top: 15px;"><span style="background-color: rgb(255, 255, 255);font-family: &#34;Helvetica Neue&#34;, Helvetica, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 2px;text-align: left;">（本篇完）</span></section><section style="margin-top: 15px;"><span style="text-align: center;"></span></section>



<p><a href="2247494482">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9135637e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzIxNzUxNzA2NQ%3D%3D%26mid%3D2247494482%26idx%3D1%26sn%3D6846eec033fe7d04d70b0a5d68105b75%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 09 Sep 2021 07:44:00 +0800</pubDate>
    </item>
  </channel>
</rss>