跳到正文
原文
Michael Bargury· @mbrg0 · X·本站收录 · 原文发表

安全公司 Armadin 用智能体集群持续扫描网络,在攻击者之前判断漏洞可利用性

AI 导读

安全公司 Armadin 的 Kevin Mandia 介绍了一种“超攻击”(hyperattack)做法:向目标网络投放智能体集群,测绘其所有服务、路由、系统和资产,随后像心跳一样持续轮询这些元数据,捕捉应用、路由或服务的变更,再针对变化发起攻击。Mandia 称,在 AI 时代需要的是模型持续施压,在威胁变化、新模型出现、有新情报或网络变动时触发。他提到上周末某流行产品出现零日漏洞后,其心跳机制立即轮询出受影响对象。Armadin 的目标是在攻击者之前,从已知漏洞推进到判断其是否真正可被利用。

正文

don't worry, these are good swarms

none of those baddies looting for info about The Scorer

引用a16z@a16z
Kevin Mandia on why companies need an agent swarm polling their network like a heartbeat, because the window to catch a new security hole keeps shrinking: "We do a thing called a hyperattack. That's just a fancy word for we throw a drone swarm of agents at you, and we map your network. Every service, every route, every system, all assets." "With that metadata, we now just poll you almost like a heartbeat. What's changed? Did an app change? Did a route change? Did a service get updated? So that we can poll cheaply for change and then attack the change." "What you really want in the AI age is the constant pressure of models attacking you... You do it when either the threat changes, new models come out, new intelligence is available, or your network changes." "That's what we had over the weekend. There was a zero-day in a popular product, and immediately we've already got the heartbeat. We just polled who's got the problem." "Our goal at Armadin is to go from a known vulnerability to knowing whether it's actually exploitable before the bad guys can." @ArmadinSecurity @DavidGeorge83
在 X 查看被引用的帖子

来源:Michael Bargury · x.com