a16z 对谈 Kevin Mandia:AI 智能体集群如何应对漏洞利用窗口收缩
Mandia 在 a16z 的访谈里讲了个有意思的思路:用一群智能体像心跳一样盯着你的网络,有变化就先攻击测试,赶在黑客前面。87% vs 23% 这组数字挺扎眼。
a16z 发布的对话中,Kevin Mandia 介绍其公司 Armadin 的 hyperattack 方法:用无人机集群式的智能体扫描并映射企业网络的全部服务、路由和资产。建立元数据后,系统像心跳一样持续轮询网络变化,一旦发现新改动就针对该改动发起攻击测试。数据显示黑客实际利用的漏洞中约 87% 在漏洞公开当天或之前就遭攻击,而 2020 年这一比例只有 23%。文中举例称某热门产品爆出 zero-day 后,团队已通过心跳轮询锁定受影响对象。
The window to patch software bugs is collapsing Of the bugs hackers actually exploit, ~87% are now being attacked on or before the day the bug is public knowledge That share was 23% in 2020 a16z @a16z Kevin Mandia on why companies need an agent swarm polling their network like a heartbeat, because the window to catch a new security hole keeps shrinking: "We do a thing called a hyperattack. That's just a fancy word for we throw a drone swarm of agents at you, and we map your network. Every service, every route, every system, all assets." "With that metadata, we now just poll you almost like a heartbeat. What's changed? Did an app change? Did a route change? Did a service get updated? So that we can poll cheaply for change and then attack the change." "What you really want in the AI age is the constant pressure of models attacking you... You do it when either the threat changes, new models come out, new intelligence is available, or your network changes." "That's what we had over the weekend. There was a zero-day in a popular product, and immediately we've already got the heartbeat. We just polled who's got the problem." "Our goal at Armadin is to go from a known vulnerability to knowing whether it's actually exploitable before the bad guys can." @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 6 🔄 2 ❤️ 17 👀 5534 📊 6 ⚡