RSAC2022 | Ò»ÎĶÁ¶®¡°ÈȶȸßÕÇ¡±µÄÈí¼þ¹©¸øÁ´°²È«
°ä²¼¹¦·ò 2022-06-22¿´RSACÈôºÎÍÆ¶¯Èí¼þ¹©¸øÁ´°²È«·¢Õ¹
ÓÉÓÚÈí¼þ¹©¸øÁ´µÄ¹¥»÷ÁìÓò¹ã¡¢·½Ê½Òñ±Î¡¢·çÏմ󣬣¬£¬£¬£¬¸øÆóÒµ°²È«·À»¤´øÀ´Á˼«´óµÄÌôÕ½£¬£¬£¬£¬£¬ËùÒÔ×öºÃÈí¼þ¹©¸øÁ´°²È«µÄ·À»¤ÊÆÔÚ±ØÐУ¬£¬£¬£¬£¬ÒÔÉ«Áй«Ë¾CycodeҲƾ½èÈí¼þ¹©¸øÁ´°²È«µÄ¸ÅÏëÓÖÒ»´ÎÈëΧɳºÐ´´ÐÂʮǿ¡£¡£¡£¡£¡£ÏÂÃæ´ÓRSACÀú½ìDevSecOps½â¾ö¹æ»®³§É̵Ä˼·À´¿´Èí¼þ¹©¸øÁ´°²È«µÄ¼¼Êõ·¢Õ¹Ç÷Ïò¡£¡£¡£¡£¡£
ÔçÔÚ2017Ä꣬£¬£¬£¬£¬DevSecOps¾Í±»RSACËùÒýÈ룬£¬£¬£¬£¬»áÉÏÃ÷È·ÁËDevSecOpsʵ¼ÊµÄÖ÷ÌåÄÚÈÝ£¬£¬£¬£¬£¬²¢Ìá³öÁË×óÒÆ°²È«Ç°ÖõÄ˼Ïë¡£¡£¡£¡£¡£
ÔÚ2018ÄêRSACÉϸüÊÇͨ¹ý¡°Golden Pipeline¡±µÄ¸ÅÏ룬£¬£¬£¬£¬Ç¿µ÷ÔÚÈí¼þ¹©¸øÁ´°²È«ÉÏ£¬£¬£¬£¬£¬×Ô¶¯»¯¹¤¾ßÊDZز»³ÉÉٵ쬣¬£¬£¬£¬ÆäÖÐCyberGRX×÷ΪµÚÈý·½ÍøÂç·çÏÕÖÎÀíÆ½Ì¨ÔÚ´ó»áÉÏո¶ͷ½Ç£¬£¬£¬£¬£¬Ëü´ÓÔ®ÊÔìóÒ·í½âºÍÖÎÀí¹©¸øÁ´ÍþÐ²ÔØÌåΪÆô³Ìµã£¬£¬£¬£¬£¬Í¨¹ý¶ÔÆóÒµÈí¼þ¹©¸øÉ̽øÐÐÈ«Ãæµ÷²é£¬£¬£¬£¬£¬´ï³ÉÌáÔçʵÏÖÍþв֪̽µÄÖ÷ÕÅ¡£¡£¡£¡£¡£
2019ÄêRSACÖÐÌØÉèµÄ×ÓÖ÷Ìâ¡°DevOps Connect¡±£¬£¬£¬£¬£¬DevSecOps½øÈëµ½È«Ãæ·¢×÷ÆÚ£¬£¬£¬£¬£¬»áÒéÇ¿µ÷ÁËDevSecOpsÂäµØÊµ¼Ê¹ý³ÌÖÐÎÄ»¯ÈںϵÄÒâ˼£¬£¬£¬£¬£¬²¢½øÕ¹Í¨¹ýCI/CD¹Ü·¸¨ÒÔÓÐЧ¶ÈÁ¿»úÔìÀ´ÊµÏÖЧÄÜÉϵÄÌáÉý
DevSecOpsÔÚ¹úÄڵķ¢Õ¹Çé¿ö
ÔÚDevSecOps¹ÄÆðµÄº£³±Ï£¬£¬£¬£¬£¬Ô½À´Ô½¶àÆóÒµ½«ËüÀûÓõ½×ÔÉíµÄ¿ª·¢°²È«¼Ü¹¹°ø±ß£¬£¬£¬£¬£¬µ«ÔÚÈÚÈëDevSecOps¿ª·¢»·¾³Ä£Ð͵Ĺý³ÌÖУ¬£¬£¬£¬£¬ÈôºÎ½â¾öÆóÒµ×ÔÉí¹©¸øÁ´°²È«µÄÎÊÌâÒ²Òý·¢Á˸÷È˵ĹØ×¢¡£¡£¡£¡£¡£
Ê×ÏÈÊÇÎÄ»¯Èںϡ£¡£¡£¡£¡£¶àËùÖÜÖª£¬£¬£¬£¬£¬È˵ÄÐÔ×ÓÊÇϲ»¶´ýÔÚ×ÔÉí¿ÉÕÆ¿ØµÄÊæ·þÇø¡£¡£¡£¡£¡£Èç½ñ´ó²¿·ÔìóҵתÏòDevSecOpsµÄÍ·ºÅÌôÕ½£¬£¬£¬£¬£¬À´×ÔÎÄ»¯²ãÃæµÄµÖ´¥¸ÐÇé¡£¡£¡£¡£¡£ºÜ¶àÈËÒÔΪ°²È«±£ÏÕ»áÍÏÂýÈí¼þ¿ª·¢¹¤×÷ËÙ¶È¡¢ÉõÖÁ¹ÊÕÏ×ÔÉí´´Ð¡£¡£¡£¡£¡£
Æä´Î£¬£¬£¬£¬£¬DevSecOpsÇ¿µ÷¿ª·¢ÈËÔ±Ó밲ȫר¼ÒͳһºÏ×÷£¬£¬£¬£¬£¬¶þÕß¹²Í¬³ÉÁ¢ÆðºÏ×÷»·¾³¡£¡£¡£¡£¡£µ«ÔÚÁ½´óÍŶӼä×ÜÊÇ´æÔڿ϶¨Ë®Æ½µÄĦ²Á£¬£¬£¬£¬£¬ÉõÖÁÒÔΪ¶Ô·½×ÜÔÚ¸ú×Ô¼º×÷¶Ô¡£¡£¡£¡£¡£¾Ù¸öÀý×Ó£ºÀýÈçÈí¼þ±í°ü¹«Ë¾µÄÊ×ÒªÖ¸±êÊÇÂú×ã¿Í»§µÄÒµÎñÐèÒª£¬£¬£¬£¬£¬¿ª·¢ÈËÔ±µ«Ô¸²»ÐÝÌáÉý´úÂëµÄ½»¸¶ËÙ¶È¡£¡£¡£¡£¡£µ«ÊÇÔÚ°²È«ÍŶӿ´À´£¬£¬£¬£¬£¬ËûÃǵŤ×÷³ÁµãÔÚÓÚ±£ÏÕ´úÂëµÄ°²È«£¬£¬£¬£¬£¬¶øÕâÁ½¸ö½ØÈ»·ÖÆçµÄÖ¸±êµ¼ÖÂÍŶÓÖ®¼äÄÑÒԱ˴ËÀí½â¡¢Ðͬ¹¤×÷¡£¡£¡£¡£¡£
ÔٴΣ¬£¬£¬£¬£¬°²È«ÈËÔ±µÄ²»¼°Ò²¿ÉÄÜÓ°ÏìDevSecOpsµÄ½¨Éè¡£¡£¡£¡£¡£Ö»¹ÜºÃ¶àÆóÒµÔÚ´ÓÊÂDevSecOpsµÄÂ䵨¹¤×÷£¬£¬£¬£¬£¬µ«ÈËÔ±ÄÜÁ¦Ë®Æ½²Î²î²»Æë£¬£¬£¬£¬£¬ÖªÊ¶´¢ÐîµÍϵÄÇé¿öΪÆóÒµÔì³ÉÁ˲»Ó×µÄÂé·³¡£¡£¡£¡£¡£¾Ý¡¶ÍøÂçÐÅÏ¢°²È«È˲ŷ¢Õ¹»ã±¨¡·Ö¸³ö£¬£¬£¬£¬£¬ÎÒ¹úÍøÂ簲ȫÈ˲ÅÈÔ´¦ÓÚ¹©²»Ó¦ÇóµÄ״̬¡£¡£¡£¡£¡£
×îºó£¬£¬£¬£¬£¬DevSecOpsÔÚʵ¼Ê¹ý³ÌÖÐÓöµ½µÄÁíÒ»¸öÌôÕ½ÊÇ×Ô¶¯»¯¹¤¾ßµÄ²»¼°¡£¡£¡£¡£¡£DevSecOps¼«¶ÈÒÀÀµ×Ô¶¯»¯¹¤¾ßÀ´ÊµÏÖ°æ±¾ÖÎÀí¡¢È±µãÖÎÀí¡¢´úÂë¹¹½¨¡¢·ì϶ɨÃèµÈ¹¤×÷¡£¡£¡£¡£¡£Ö»¹Ü¹©¸øÁ´°²È«ÁìÓòһЩ¿ªÄܹ»ÕÒµ½Ò»Ð©¿ªÔ´ºÍóÒ×¹¤¾ß£¬£¬£¬£¬£¬µ«ÔÚ¹ú²ú»¯µÄÐÐÒµ²¼¾°Ï£¬£¬£¬£¬£¬ÕâЩ¹¤¾ß´æÔÚ¹¦Â䵨µÄÏÖʵÐèÒª¡£¡£¡£¡£¡£
ʹÓÃDevSecOpsÀíÏ뽨ÉèÈí¼þ¹©¸øÁ´°²Õû¸öϵ
ƾ¾ÝRSAC»ýÄêµÄDevSecOpsÀíÏ룬£¬£¬£¬£¬Óйص¥ÔªÒª×öºÃÈí¼þ¹©¸øÁ´¼¼Êõ²úÆ·µÄ°²È«¿ª·¢ÍùÍù±ØÒª´ÓÖÎÀí²ãÃæºÍ¼¼Êõ²ãÃæÆô³Ì£¬£¬£¬£¬£¬·¢Õ¹ÏµÍ³»¯µÄ½¨É蹤×÷¡£¡£¡£¡£¡£
? Èí¼þ¹©¸øÁ´°²È«ÖÎÀí·½Ãæ
1¡¢¼ÓÇ¿°²È«¿ª·¢»·¾³µÄ¿É¿ØÐÔ
ÔÚÈí¼þ¿ª·¢½×¶ÎÐèÉèÖÃÓа²È«¿É¿ØµÄ¹¤×÷³¡Ëù£¬£¬£¬£¬£¬²¢Õë¶Ô¿ª·¢¹ý³Ì´î½¨×¨ÓõĿª·¢»·¾³ºÍ²âÊÔ»·¾³£¬£¬£¬£¬£¬½¨É谲ȫ¡¢¿ÉÐÅ¡¢¿¿µÃסµÄ°²È«¿ª·¢¹¤¾ß£¬£¬£¬£¬£¬ÉèÖð´½ÇÉ«·ÖÅäµÄºÏÀíȨÏÞ£¬£¬£¬£¬£¬È·±£¿£¿£¿£¿£¿ª·¢¹ý³ÌºÍ²âÊÔ¹ý³Ì¿É¿Ø£¬£¬£¬£¬£¬±£ÏÕÈí¼þÑз¢×ʲú°²È«¡£¡£¡£¡£¡£
2¡¢¼ÓÇ¿ÖÊÁ¿ÖÎÀíϵͳÈÚºÏ
ƾ¾ÝÈí¼þ¹©¸øÁ´°²È«µÄ¿ª²úÐÔÃüÖÜÆÚ³ÉÁ¢ºÏÀíµÄ×éÖ¯¼Ü¹¹ºÍÖÎÀí¼Ü¹¹À´Âú×ã²úÆ·°²È«¿ª·¢µÄÖ´ÐкÍÖÎÀí¡£¡£¡£¡£¡£
3¡¢¼ÓÇ¿°²È«¿ª·¢¼¼ÊõÅàѵ
¸øËùÓеÄÑз¢ÈËÔ±ÅàѵDevSecOps²½ÖèÁ÷³Ì£¬£¬£¬£¬£¬ÈÃÿ¸öÑз¢ÈËԱʵÏÖ»¥¶¯¹ØÏµ£¬£¬£¬£¬£¬Ò²ÈÃÿ¸öÑз¢ÈËÔ±Àí½âDevSecOps µÄ¹¤×÷ÒÔ¼°¶ÔÕûÌå²úÆ·°²È«Ö÷ÌåµÄÀí½â¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ª·¢ÈËÔ±ÏàʶÏß³ÌÄ£ÐͺͺϹæÐԲ鳣¬£¬£¬£¬£¬²¢ÏàʶÈôºÎºâÁ¿·çÏÕÒÔ¼°ÈôºÎÖ´Ðа²È«½ÚÔ죬£¬£¬£¬£¬´Ó¶øÈ·±£×éÖ¯ÖеÄËùÓÐÈËÏàʶ¹«Ë¾µÄ°²È«Çé¿ö£¬£¬£¬£¬£¬×ñÑÒ»ÑùµÄ³ß¶È¡£¡£¡£¡£¡£
? Èí¼þ¿ª·¢¼¼Êõ·½Ãæ
?
1¡¢¹¹½¨¾ßÌåµÄÈí¼þÎïÁÏÇåµ¥
Èí¼þ¹©¸øÁ´°²È«Ê¼ÓڶԹؼü»·½ÚµÄ¿É¼ûÐÔ£¬£¬£¬£¬£¬ÆóÒµ±ØÒªÎªÃ¿¸öÀûÓ÷¨Ê½³ÖÐø¹¹½¨¾ßÌåµÄ SBOM£¨Software Bill of Material£¬£¬£¬£¬£¬Èí¼þÎïÁÏÇåµ¥£©´Ó¶øÈ«Ãæ¶´²ìÿ¸öÀûÓÃÈí¼þµÄ×é¼þÇé¿ö£¬£¬£¬£¬£¬ÎªÍ»·¢µÄ·ì϶Ìṩ¸ø¼±µÄ´ëÊ©¡£¡£¡£¡£¡£
2¡¢ºÏÀíʹÓúð²È«¿ª·¢¹¤¾ß
×Ô¶¯»¯¹¤¾ßµÄʹÓ㬣¬£¬£¬£¬¿ÉÓÐЧÏ÷¼õÈËΪ¼ì²âµÄ¹¦·ò¿÷ËðºÍ³É±¾Í¶È룬£¬£¬£¬£¬Ìá¸ß¼ì²âЧÄÜ¡£¡£¡£¡£¡£Èí¼þ°²È«¿ª·¢ÁìÓò³£¼ûµÄ°²È«¿ª·¢¹¤¾ß£¬£¬£¬£¬£¬Ê¹Óõļ¼ÊõÔ̺¬£ºSAST¼¼Êõ¡¢DAST¼¼Êõ¡¢IAST¼¼ÊõºÍFUZZ¼¼Êõ¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬±£ÏÕÈí¼þ¹©¸øÁ´°²È«£¬£¬£¬£¬£¬ÐèÔÚDevSecOpsµÄ·ÖÆç½×¶ÎÀûÓÃ·ÖÆçµÄ×Ô¶¯»¯°²È«¼¼Êõ¡£¡£¡£¡£¡£
? ¹©¸øÉÌÖÎÀí·½Ãæ
Õë¶ÔÈí¼þµÄÌṩÉ̽øÐÐÑϸñµÄÉóºË£¬£¬£¬£¬£¬Ô̺¬´Ó²ÆÕþʵÁ¦¡¢ÖÊÁ¿³Ðŵ¡¢ÆóÒµ×ÊÖÊ¡¢¼¼Êõ´¢ÐîµÈ·½Ã棬£¬£¬£¬£¬Í¨¹ýµ÷²éÈí¼þ¹©¸øÉ̵Ä×ÛºÏʵÁ¦£¬£¬£¬£¬£¬ÒÔÑ¡Ôñ×îÏàÒ˵ĺÏ×÷ͬ°é£¬£¬£¬£¬£¬±£ÏÕÈí¼þ²úÆ·µÄ°²È«ÐÔ¡£¡£¡£¡£¡£
RSAC´´ÐÂɳºÐ³ÖÐø¹Ø×¢ÍøÂ簲ȫÐÐÒµÈȵ㷽Ïò£¬£¬£¬£¬£¬ÒýÁì¼¼Êõ´´Ð£¬£¬£¬£¬£¬ÎªÈí¼þ¹©¸øÁ´°²È«µÄ¼¼ÊõʵÏÖÌṩÁË¿ÉÐеĽâ¾ö¹æ»®¡£¡£¡£¡£¡£ÏàÐŽ«À´»áÓиü¶àµÄÈí¼þ¹©¸øÁ´°²È«³§ÉÌÈëΧ´´ÐÂɳºÐ£¬£¬£¬£¬£¬Íƶ¯¸ü¶à´´Ð¼¼ÊõµÄ·¢Õ¹¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ