RSAC2022 | Ò»ÎĶÁ¶®¡°ÈȶȸßÕÇ¡±µÄÈí¼þ¹©¸øÁ´°²È«
°ä²¼¹¦·ò 2022-06-22¿´RSACÈôºÎÍÆ¶¯Èí¼þ¹©¸øÁ´°²È«·¢Õ¹
ÓÉÓÚÈí¼þ¹©¸øÁ´µÄ¹¥»÷ÁìÓò¹ã¡¢·½Ê½Òñ±Î¡¢·çÏմ󣬸øÆóÒµ°²È«·À»¤´øÀ´Á˼«´óµÄÌôÕ½£¬ËùÒÔ×öºÃÈí¼þ¹©¸øÁ´°²È«µÄ·À»¤ÊÆÔÚ±ØÐУ¬ÒÔÉ«Áй«Ë¾CycodeҲƾ½èÈí¼þ¹©¸øÁ´°²È«µÄ¸ÅÏëÓÖÒ»´ÎÈëΧɳºÐ´´ÐÂʮǿ¡£ÏÂÃæ´ÓRSACÀú½ìDevSecOps½â¾ö¹æ»®³§É̵Ä˼·À´¿´Èí¼þ¹©¸øÁ´°²È«µÄ¼¼Êõ·¢Õ¹Ç÷Ïò¡£
ÔçÔÚ2017Ä꣬DevSecOps¾Í±»RSACËùÒýÈ룬»áÉÏÃ÷È·ÁËDevSecOpsʵ¼ÊµÄÖ÷ÌåÄÚÈÝ£¬²¢Ìá³öÁË×óÒÆ°²È«Ç°ÖõÄ˼Ïë¡£
ÔÚ2018ÄêRSACÉϸüÊÇͨ¹ý¡°Golden Pipeline¡±µÄ¸ÅÏ룬ǿµ÷ÔÚÈí¼þ¹©¸øÁ´°²È«ÉÏ£¬×Ô¶¯»¯¹¤¾ßÊDZز»³ÉÉٵ쬯äÖÐCyberGRX×÷ΪµÚÈý·½ÍøÂç·çÏÕÖÎÀíÆ½Ì¨ÔÚ´ó»áÉÏո¶ͷ½Ç£¬Ëü´ÓÔ®ÊÔìóÒ·í½âºÍÖÎÀí¹©¸øÁ´ÍþÐ²ÔØÌåΪÆô³Ìµã£¬Í¨¹ý¶ÔÆóÒµÈí¼þ¹©¸øÉ̽øÐÐÈ«Ãæµ÷²é£¬´ï³ÉÌáÔçʵÏÖÍþв֪̽µÄÖ÷ÕÅ¡£
2019ÄêRSACÖÐÌØÉèµÄ×ÓÖ÷Ìâ¡°DevOps Connect¡±£¬DevSecOps½øÈëµ½È«Ãæ·¢×÷ÆÚ£¬»áÒéÇ¿µ÷ÁËDevSecOpsÂäµØÊµ¼Ê¹ý³ÌÖÐÎÄ»¯ÈںϵÄÒâ˼£¬²¢½øÕ¹Í¨¹ýCI/CD¹Ü·¸¨ÒÔÓÐЧ¶ÈÁ¿»úÔìÀ´ÊµÏÖЧÄÜÉϵÄÌáÉý
DevSecOpsÔÚ¹úÄڵķ¢Õ¹Çé¿ö
ÔÚDevSecOps¹ÄÆðµÄº£³±Ï£¬Ô½À´Ô½¶àÆóÒµ½«ËüÀûÓõ½×ÔÉíµÄ¿ª·¢°²È«¼Ü¹¹°ø±ß£¬µ«ÔÚÈÚÈëDevSecOps¿ª·¢»·¾³Ä£Ð͵Ĺý³ÌÖУ¬ÈôºÎ½â¾öÆóÒµ×ÔÉí¹©¸øÁ´°²È«µÄÎÊÌâÒ²Òý·¢Á˸÷È˵ĹØ×¢¡£
Ê×ÏÈÊÇÎÄ»¯Èںϡ£¶àËùÖÜÖª£¬È˵ÄÐÔ×ÓÊÇϲ»¶´ýÔÚ×ÔÉí¿ÉÕÆ¿ØµÄÊæ·þÇø¡£Èç½ñ´ó²¿·ÔìóҵתÏòDevSecOpsµÄÍ·µÈÌôÕ½£¬À´×ÔÎÄ»¯²ãÃæµÄµÖ´¥¸ÐÇé¡£ºÜ¶àÈËÒÔΪ°²È«±£ÏÕ»áÍÏÂýÈí¼þ¿ª·¢¹¤×÷¿ìÂÊ¡¢ÉõÖÁ¹ÊÕÏ×ÔÉí´´Ð¡£
Æä´Î£¬DevSecOpsÇ¿µ÷¿ª·¢ÈËÔ±Ó밲ȫר¼ÒͳһºÏ×÷£¬¶þÕß¹²Í¬³ÉÁ¢ÆðºÏ×÷»·¾³¡£µ«ÔÚÁ½´óÍŶӼä×ÜÊÇ´æÔڿ϶¨Ë®Æ½µÄĦ²Á£¬ÉõÖÁÒÔΪ¶Ô·½×ÜÔÚ¸ú×Ô¼º×÷¶Ô¡£¾Ù¸öÀý×Ó£ºÀýÈçÈí¼þ±í°ü¹«Ë¾µÄÊ×ÒªÖ¸±êÊÇÂú×ã¿Í»§µÄÒµÎñÐèÒª£¬¿ª·¢ÈËÔ±µ«Ô¸²»ÐÝÌáÉý´úÂëµÄ½»¸¶¿ìÂÊ¡£µ«ÊÇÔÚ°²È«ÍŶӿ´À´£¬ËûÃǵŤ×÷³ÁµãÔÚÓÚ±£ÏÕ´úÂëµÄ°²È«£¬¶øÕâÁ½¸ö½ØÈ»·ÖÆçµÄÖ¸±êµ¼ÖÂÍŶÓÖ®¼äÄÑÒԱ˴ËÀí½â¡¢Ðͬ¹¤×÷¡£
ÔٴΣ¬°²È«ÈËÔ±µÄ²»¼°Ò²¿ÉÄÜÓ°ÏìDevSecOpsµÄ½¨Éè¡£Ö»¹ÜºÃ¶àÆóÒµÔÚ´ÓÊÂDevSecOpsµÄÂ䵨¹¤×÷£¬µ«ÈËÔ±ÄÜÁ¦Ë®Æ½²Î²î²»Æë£¬ÖªÊ¶´¢ÐîµÍϵÄÇé¿öΪÆóÒµÔì³ÉÁ˲»Ó×µÄÂé·³¡£¾Ý¡¶ÍøÂçÐÅÏ¢°²È«È˲ŷ¢Õ¹»ã±¨¡·Ö¸³ö£¬ÎÒ¹úÍøÂ簲ȫÈ˲ÅÈÔ´¦ÓÚ¹©²»Ó¦ÇóµÄ״̬¡£
×îºó£¬DevSecOpsÔÚʵ¼Ê¹ý³ÌÖÐÓöµ½µÄÁíÒ»¸öÌôÕ½ÊÇ×Ô¶¯»¯¹¤¾ßµÄ²»¼°¡£DevSecOps¼«¶ÈÒÀÀµ×Ô¶¯»¯¹¤¾ßÀ´ÊµÏÖ°æ±¾ÖÎÀí¡¢È±µãÖÎÀí¡¢´úÂë¹¹½¨¡¢·ì϶ɨÃèµÈ¹¤×÷¡£Ö»¹Ü¹©¸øÁ´°²È«ÁìÓòһЩ¿ªÄܹ»ÕÒµ½Ò»Ð©¿ªÔ´ºÍóÒ×¹¤¾ß£¬µ«ÔÚ¹ú²ú»¯µÄÐÐÒµ²¼¾°Ï£¬ÕâЩ¹¤¾ß´æÔÚ¹¦Â䵨µÄÏÖʵÐèÒª¡£
ʹÓÃDevSecOpsÀíÏ뽨ÉèÈí¼þ¹©¸øÁ´°²Õû¸öϵ
ƾ¾ÝRSAC»ýÄêµÄDevSecOpsÀíÏ룬Óйص¥ÔªÒª×öºÃÈí¼þ¹©¸øÁ´¼¼Êõ²úÆ·µÄ°²È«¿ª·¢ÍùÍù±ØÒª´ÓÖÎÀí²ãÃæºÍ¼¼Êõ²ãÃæÆô³Ì£¬·¢Õ¹ÏµÍ³»¯µÄ½¨É蹤×÷¡£
? Èí¼þ¹©¸øÁ´°²È«ÖÎÀí·½Ãæ
1¡¢¼ÓÇ¿°²È«¿ª·¢»·¾³µÄ¿É¿ØÐÔ
ÔÚÈí¼þ¿ª·¢½×¶ÎÐèÉèÖÃÓа²È«¿É¿ØµÄ¹¤×÷³¡Ëù£¬²¢Õë¶Ô¿ª·¢¹ý³Ì´î½¨×¨ÓõĿª·¢»·¾³ºÍ²âÊÔ»·¾³£¬½¨É谲ȫ¡¢¿ÉÐÅ¡¢¿¿µÃסµÄ°²È«¿ª·¢¹¤¾ß£¬ÉèÖð´½ÇÉ«·ÖÅäµÄºÏÀíȨÏÞ£¬È·±£¿ª·¢¹ý³ÌºÍ²âÊÔ¹ý³Ì¿É¿Ø£¬±£ÏÕÈí¼þÑз¢×ʲú°²È«¡£
2¡¢¼ÓÇ¿ÖÊÁ¿ÖÎÀíϵͳÈÚºÏ
ƾ¾ÝÈí¼þ¹©¸øÁ´°²È«µÄ¿ª²úÐÔÃüÖÜÆÚ³ÉÁ¢ºÏÀíµÄ×éÖ¯¼Ü¹¹ºÍÖÎÀí¼Ü¹¹À´Âú×ã²úÆ·°²È«¿ª·¢µÄÖ´ÐкÍÖÎÀí¡£
3¡¢¼ÓÇ¿°²È«¿ª·¢¼¼ÊõÅàѵ
¸øËùÓеÄÑз¢ÈËÔ±ÅàѵDevSecOps²½ÖèÁ÷³Ì£¬ÈÃÿ¸öÑз¢ÈËԱʵÏÖ»¥¶¯¹ØÏµ£¬Ò²ÈÃÿ¸öÑз¢ÈËÔ±Àí½âDevSecOps µÄ¹¤×÷ÒÔ¼°¶ÔÕûÌå²úÆ·°²È«Ö÷ÌåµÄÀí½â¡£¿ª·¢ÈËÔ±ÏàʶÏß³ÌÄ£ÐͺͺϹæÐԲ鳣¬²¢ÏàʶÈôºÎºâÁ¿·çÏÕÒÔ¼°ÈôºÎÖ´Ðа²È«½ÚÔ죬´Ó¶øÈ·±£×éÖ¯ÖеÄËùÓÐÈËÏàʶ¹«Ë¾µÄ°²È«Çé¿ö£¬×ñÑÒ»ÑùµÄ³ß¶È¡£
? Èí¼þ¿ª·¢¼¼Êõ·½Ãæ
?
1¡¢¹¹½¨¾ßÌåµÄÈí¼þÎïÁÏÇåµ¥
Èí¼þ¹©¸øÁ´°²È«Ê¼ÓڶԹؼü»·½ÚµÄ¿É¼ûÐÔ£¬ÆóÒµ±ØÒªÎªÃ¿¸öÀûÓ÷¨Ê½³ÖÐø¹¹½¨¾ßÌåµÄ SBOM£¨Software Bill of Material£¬Èí¼þÎïÁÏÇåµ¥£©´Ó¶øÈ«Ãæ¶´²ìÿ¸öÀûÓÃÈí¼þµÄ×é¼þÇé¿ö£¬ÎªÍ»·¢µÄ·ì϶Ìṩ¸ø¼±µÄ´ëÊ©¡£
2¡¢ºÏÀíʹÓúð²È«¿ª·¢¹¤¾ß
×Ô¶¯»¯¹¤¾ßµÄʹÓ㬿ÉÓÐЧÏ÷¼õÈËΪ¼ì²âµÄ¹¦·ò¿÷ËðºÍ³É±¾Í¶È룬Ìá¸ß¼ì²âЧÄÜ¡£Èí¼þ°²È«¿ª·¢ÁìÓò³£¼ûµÄ°²È«¿ª·¢¹¤¾ß£¬Ê¹Óõļ¼ÊõÔ̺¬£ºSAST¼¼Êõ¡¢DAST¼¼Êõ¡¢IAST¼¼ÊõºÍFUZZ¼¼Êõ¡£Òò¶ø£¬±£ÏÕÈí¼þ¹©¸øÁ´°²È«£¬ÐèÔÚDevSecOpsµÄ·ÖÆç½×¶ÎÀûÓÃ·ÖÆçµÄ×Ô¶¯»¯°²È«¼¼Êõ¡£
? ¹©¸øÉÌÖÎÀí·½Ãæ
Õë¶ÔÈí¼þµÄÌṩÉ̽øÐÐÑϸñµÄÉóºË£¬Ô̺¬´Ó²ÆÕþʵÁ¦¡¢ÖÊÁ¿³Ðŵ¡¢ÆóÒµ×ÊÖÊ¡¢¼¼Êõ´¢ÐîµÈ·½Ã棬ͨ¹ýµ÷²éÈí¼þ¹©¸øÉ̵Ä×ÛºÏʵÁ¦£¬ÒÔÑ¡Ôñ×îÏàÒ˵ĺÏ×÷ͬ°é£¬±£ÏÕÈí¼þ²úÆ·µÄ°²È«ÐÔ¡£
RSAC´´ÐÂɳºÐ³ÖÐø¹Ø×¢ÍøÂ簲ȫÐÐÒµÈȵ㷽Ïò£¬ÒýÁì¼¼Êõ´´Ð£¬ÎªÈí¼þ¹©¸øÁ´°²È«µÄ¼¼ÊõʵÏÖÌṩÁË¿ÉÐеĽâ¾ö¹æ»®¡£ÏàÐŽ«À´»áÓиü¶àµÄÈí¼þ¹©¸øÁ´°²È«³§ÉÌÈëΧ´´ÐÂɳºÐ£¬Íƶ¯¸ü¶à´´Ð¼¼ÊõµÄ·¢Õ¹¡£


¾©¹«Íø°²±¸11010802024551ºÅ