SaaS 化服務:通過 Web 界面或 API 提供服務,用戶無(wu)需部署本(ben)地硬件,直接通過互聯(lian)網接入(ru)云端(duan)安(an)..關(如(ru) Zscaler、Cisco Umbrella 等(deng))。
分布(bu)式節點覆蓋(gai):在..多個(ge)數(shu)據中心(xin)部署 POP(接入點),用戶流量就近接入云端(duan)節點,經安全檢測后(hou)轉(zhuan)發(fa)至目標網(wang)站(zhan),降低延遲(chi)(如(ru)通過 Anycast 技術優(you)化路由(you))。
與(yu)云(yun)基礎設施集成:無縫(feng)對(dui)接 AWS、Azure、阿里云(yun)等云(yun)平臺,支持混(hun)合云(yun) / 多云(yun)環境下的統一安全(quan)策略。
威脅情(qing)報共(gong)享:云(yun)端(duan)匯聚用戶(hu)的(de)威脅(xie)數(shu)據(如惡意(yi) URL、釣魚頁(ye)面、勒索軟件(jian)特征),通過機器學(xue)習實時更新檢測模型(xing),提升零日攻擊識別能力(li)。
SSL/TLS 解密與檢(jian)測:在(zai)云端對加密(mi)流(liu)量(HTTPS)進行(xing)解密(mi)分析,檢測隱藏(zang)在(zai)加密(mi)通道(dao)中的惡意軟件或數據泄露行(xing)為(需用(yong)戶授權證書(shu))。
API 驅動(dong)的策(ce)略引擎:通過開放 API 接(jie)口(kou),企業可自定義安(an)全策略(如按用(yong)戶角色、設備(bei)類型、地理(li)位(wei)置(zhi)限制訪問(wen)),并(bing)與(yu)現有 IT 系(xi)統(如 AD、SIEM)聯動。
URL 過濾與內容(rong)審查:根(gen)據預定義規則(如行(xing)業合規要求(qiu)、企業風險偏好),攔截惡(e)意(yi)或違規 URL(如賭博、釣魚網站),支(zhi)持細粒(li)度分(fen)類(如 “社(she)交網絡 - 工(gong)作相關”“文件(jian)共享(xiang) - 高風險”)。
惡(e)意(yi)軟件防護:通過反病毒(du)引擎(如卡(ka)巴斯基、賽(sai)門鐵克)和沙箱分析,檢測網頁中的惡意代碼(如 JavaScript 注入、漏洞利用工具包),阻止下載惡意文(wen)件。
數據防(fang)泄露(lu)(DLP):掃描上傳 / 下載的文(wen)(wen)件內容(rong),阻止敏(min)感數據(如(ru)(ru)信用卡號、醫療(liao)記錄)通(tong)過(guo) Web 表單或(huo)文(wen)(wen)件傳輸泄露,支持(chi)自定義(yi)數據指(zhi)紋(如(ru)(ru)正則(ze)表達(da)式(shi)匹配)。
零信任訪問控制:基(ji)于 “持續驗證(zheng),永不信任” 原則,結合設備狀態(如是否安裝殺毒(du)軟件)、用戶(hu)身份(多因(yin)素..)和環境風(feng)險(如異(yi)常地理(li)位置登錄)動態授(shou)權訪問。
..威(wei)脅檢測:利用行為分析(如用戶異(yi)常訪問(wen)模式)和威(wei)脅關聯引擎,識別供應鏈攻(gong)擊(ji)、APT(..持續性威(wei)脅)等復(fu)雜(za)攻(gong)擊(ji)鏈。例如,檢測同一(yi) IP 短(duan)時間內頻繁訪問(wen)多(duo)個高危(wei)站點。
合規性審計:生成詳(xiang)細(xi)日志報告(如(ru)用戶訪問記錄、威脅(xie)事件詳(xiang)情),滿足 GDPR、等保 2.0、HIPAA 等合規(gui)要求,支持日志一鍵導出(chu)至 SIEM 系統。
緩存與加速:緩(huan)存靜(jing)態內(nei)容(如圖(tu)片、CSS/JS 文件),減(jian)少重復(fu)下載,提升網頁加(jia)載速度(尤其適用于(yu)跨國訪問場景)。
流量(liang)清洗:通過(guo)(guo)云端 DDoS 防護(hu)模(mo)塊(kuai),過(guo)(guo)濾(lv)海量惡意流量(如(ru) SYN Flood、HTTP Flood),保(bao)障企業 Web 服務可用性。
維(wei)度 | 云計算 Web 安..關 | 傳統硬(ying)件(jian)網關 |
---|---|---|
部署(shu)成本(ben) | 零硬件投入,按需付費(OPEX 模式) | 高初期投資(CAPEX),需定期升級 |
擴展性(xing) | 彈性擴展,支持千萬級并發 | 受限于硬件性能,擴容復雜 |
威脅響應速度(du) | 分鐘級..規則更新,實時威脅情報共享 | 依賴手動更新,區域化響應延遲 |
分布式部署 | 天然支持多分支機構、遠程辦公安全接入 | 需在每個節點部署硬件設備 |
管(guan)理復(fu)雜度 | 云端統一管理,策略實時生效 | 多設備獨立配置,策略同步困難 |
分布式(shi)企業安全(quan)接入:跨國(guo)公(gong)司(si)分支機構或遠程員工通(tong)過云端網(wang)關(guan)訪問(wen)互聯網(wang),無需在每個辦公(gong)室部署硬件設備,統一策略下(xia)發(fa)(如禁止訪問(wen) P2P 下(xia)載站點)。
移(yi)動辦公安(an)全:員工(gong)通過手機、平(ping)(ping)板等移動設備接入時,云端(duan)網關提供跨平(ping)(ping)臺的一致安(an)全防護(如阻止移動設備訪問惡意 APK 下(xia)載頁面)。
多云環境安(an)全(quan):企業使用 AWS、Azure 等多(duo)個云(yun)(yun)(yun)平(ping)臺時(shi),云(yun)(yun)(yun)端網(wang)關作(zuo)為統(tong)一安全(quan)入口(kou),避免不同云(yun)(yun)(yun)環境下(xia)的策略孤(gu)島。
中小企(qi)業(ye)輕量化安(an)全:無需專業(ye) IT 團隊維護,通過訂(ding)閱制(zhi)獲(huo)得企(qi)業(ye)級安全(quan)能力(如 URL 過濾、反惡意軟件),成本僅為硬件方(fang)案的 1/3~1/2。
用戶流(liu)量(liang)需(xu)經第(di)三方云(yun)端(duan)節點處理(li),可能涉及(ji)數(shu)(shu)(shu)據(ju)(ju)(ju)跨境(jing)傳輸(shu)合(he)規問(wen)題(如中國《數(shu)(shu)(shu)據(ju)(ju)(ju)安全法》要求重要數(shu)(shu)(shu)據(ju)(ju)(ju)本地化存儲)。需(xu)選擇(ze)支持 “區(qu)域化數(shu)(shu)(shu)據(ju)(ju)(ju)處理(li)” 的服務(wu)商(如在本地數(shu)(shu)(shu)據(ju)(ju)(ju)中心處理(li)境(jing)內流(liu)量(liang))。
云(yun)端服(fu)務商的安(an)全(quan)(quan)能(neng)力直接影(ying)響用(yong)戶(hu)數據安(an)全(quan)(quan),需驗證(zheng)其 ISO 27001、SOC 2 等..,以及數據加密措(cuo)施(shi)(如傳輸層 TLS 1.3、存儲層 AES-256)。
流量(liang)繞行云端節點可能增加(jia)延遲(chi)(尤(you)其用戶與云端 POP 距離較遠時),需(xu)服務商通過邊緣計算節點(Edge POP)或(huo) Anycast 技術(shu)優化(hua)路由(理想(xiang)情況下延遲(chi)增加(jia) < 5ms)。
SSL 解密(mi)(mi)可能消(xiao)耗(hao)云(yun)端算力,需關注服務商的并(bing)發處理能力(如單節點支持 10Gbps 解密(mi)(mi)吞吐量)。
企(qi)業網(wang)絡(luo)中斷時,云端網(wang)關無(wu)法(fa)提供服務,需結合本地緩存或備用(yong)鏈路(如 SD-WAN)..業務連(lian)續性。
Zscaler Internet Access(ZIA):純云端架構,主打零信任訪問,支持實(shi)時威(wei)脅(xie)檢測與數(shu)據防泄露(lu), POP 節點超 200 個。
Cisco Umbrella:整合域名解析層(ceng)安(an)全(DNS 過濾)與 Web 安(an)..關,通過 Anycast 網(wang)絡(luo)降低(di)延遲,適合混合云(yun)環境。
Forcepoint SWG:提供深度(du)內容(rong)檢(jian)測(如文檔沙箱分析),支持自(zi)定義(yi)策略引(yin)擎,滿足金融、政府(fu)等高(gao)合規(gui)需求(qiu)。
Symantec Web Security Service:依托賽(sai)門鐵克..威脅情報(bao),主打惡(e)意軟件防(fang)護與合(he)規(gui)審計,適合(he)中(zhong)小企業。
與 SASE(安(an)全訪問(wen)服務邊緣)融合:Web 作為 SASE 架(jia)構的(de)核(he)心(xin)組件,與 SD-WAN、零信任網絡訪問(ZTNA)等功能集(ji)成(cheng),提(ti)供端到端安全接入(ru)。
AI 驅動的威脅檢測(ce):利用(yong) NLP 分(fen)(fen)析(xi)網頁內容(rong)語義(如釣魚(yu)郵件中的社會工程話術(shu)),結合行(xing)為分(fen)(fen)析(xi)模(mo)型(xing)識別新型(xing)攻擊。
無客戶端(duan)部署:通過(guo)瀏覽(lan)器插件或 API 集成,簡化用(yong)戶接(jie)入流(liu)程,尤其適(shi)用(yong)于 BYOD(自帶設備)場景(jing)。
一(yi)(yi)、技(ji)(ji)術(shu)(shu)架(jia)構(gou)與(yu)(yu)(yu)(yu)(yu)核(he)(he)(he)心(xin)(xin)原理(li)
1. 云(yun)(yun)(yun)(yun)(yun)端(duan)部署模(mo)式(shi)
SaaS 化(hua)(hua)服(fu)(fu)(fu)務(wu)(wu):通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo) Web 界(jie)面或 API 提(ti)供(gong)服(fu)(fu)(fu)務(wu)(wu),用(yong)戶(hu)無(wu)需(xu)(xu)(xu)(xu)(xu)部署本(ben)(ben)地(di)硬(ying)件(jian)(jian)(jian)(jian),直(zhi)接(jie)(jie)通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)互聯網(wang)(wang)接(jie)(jie)入(ru)云(yun)(yun)(yun)(yun)(yun)端(duan)安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) Zscaler、Cisco Umbrella 等)。
分(fen)布(bu)式(shi)節(jie)(jie)點(dian)覆蓋:在(zai)(zai)..多(duo)個數(shu)(shu)(shu)據(ju)(ju)(ju)中(zhong)(zhong)(zhong)心(xin)(xin)部署 POP(接(jie)(jie)入(ru)點(dian)),用(yong)戶(hu)流(liu)(liu)量(liang)(liang)就近接(jie)(jie)入(ru)云(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)點(dian),經安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)檢(jian)測后轉發(fa)至目(mu)標(biao)網(wang)(wang)站(zhan),降(jiang)低(di)延(yan)(yan)遲(chi)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo) Anycast 技(ji)(ji)術(shu)(shu)優(you)(you)化(hua)(hua)路由)。
與(yu)(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)基(ji)礎設(she)(she)施集成(cheng)(cheng):無(wu)縫對接(jie)(jie) AWS、Azure、阿里云(yun)(yun)(yun)(yun)(yun)等云(yun)(yun)(yun)(yun)(yun)平(ping)臺(tai)(tai)(tai),支(zhi)(zhi)持混合(he)(he)(he)(he)(he)云(yun)(yun)(yun)(yun)(yun) / 多(duo)云(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)(jing)(jing)下(xia)的(de)(de)(de)(de)統(tong)一(yi)(yi)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)策(ce)(ce)(ce)略(lve)(lve)。
2. 核(he)(he)(he)心(xin)(xin)技(ji)(ji)術(shu)(shu)支(zhi)(zhi)撐
威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)情報(bao)(bao)共享(xiang):云(yun)(yun)(yun)(yun)(yun)端(duan)匯(hui)聚..用(yong)戶(hu)的(de)(de)(de)(de)威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)數(shu)(shu)(shu)據(ju)(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)惡(e)(e)(e)意(yi)(yi) URL、釣魚頁(ye)面、勒索軟件(jian)(jian)(jian)(jian)特征),通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)機(ji)器學(xue)習實(shi)(shi)時更新檢(jian)測模(mo)型(xing)(xing)(xing)(xing)(xing),提(ti)升(sheng)零(ling)日攻擊識別能(neng)(neng)(neng)力(li)(li)(li)。
SSL/TLS 解(jie)密(mi)(mi)與(yu)(yu)(yu)(yu)(yu)檢(jian)測:在(zai)(zai)云(yun)(yun)(yun)(yun)(yun)端(duan)對加(jia)(jia)密(mi)(mi)流(liu)(liu)量(liang)(liang)(HTTPS)進行(xing)(xing)解(jie)密(mi)(mi)分(fen)析,檢(jian)測隱(yin)藏在(zai)(zai)加(jia)(jia)密(mi)(mi)通(tong)(tong)(tong)(tong)道中(zhong)(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)意(yi)(yi)軟件(jian)(jian)(jian)(jian)或數(shu)(shu)(shu)據(ju)(ju)(ju)泄露行(xing)(xing)為(需(xu)(xu)(xu)(xu)(xu)用(yong)戶(hu)授權證(zheng)書)。
API 驅(qu)動(dong)(dong)(dong)(dong)的(de)(de)(de)(de)策(ce)(ce)(ce)略(lve)(lve)引擎:通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)開(kai)放 API 接(jie)(jie)口(kou),企(qi)業可自(zi)定(ding)(ding)義安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)策(ce)(ce)(ce)略(lve)(lve)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)按(an)(an)用(yong)戶(hu)角色、設(she)(she)備(bei)(bei)類型(xing)(xing)(xing)(xing)(xing)、地(di)理(li)位置(zhi)(zhi)限(xian)制(zhi)(zhi)訪(fang)(fang)問(wen)(wen)(wen)),并(bing)(bing)與(yu)(yu)(yu)(yu)(yu)現(xian)有(you) IT 系(xi)統(tong)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) AD、SIEM)聯動(dong)(dong)(dong)(dong)。
二、核(he)(he)(he)心(xin)(xin)功(gong)能(neng)(neng)(neng)與(yu)(yu)(yu)(yu)(yu)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)力(li)(li)(li)
1. 基(ji)礎安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)
URL 過(guo)(guo)(guo)(guo)濾(lv)與(yu)(yu)(yu)(yu)(yu)內(nei)容(rong)審查:根(gen)據(ju)(ju)(ju)預(yu)定(ding)(ding)義規則(ze)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)行(xing)(xing)業合(he)(he)(he)(he)(he)規要(yao)求、企(qi)業風(feng)險(xian)偏好(hao)),攔(lan)截惡(e)(e)(e)意(yi)(yi)或違規 URL(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)賭博、釣魚網(wang)(wang)站(zhan)),支(zhi)(zhi)持細粒度(du)(du)分(fen)類(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) “社(she)(she)交網(wang)(wang)絡(luo) - 工作(zuo)相關(guan)(guan)”“文件(jian)(jian)(jian)(jian)共享(xiang) - 高風(feng)險(xian)”)。
惡(e)(e)(e)意(yi)(yi)軟件(jian)(jian)(jian)(jian)防護(hu)(hu):通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)反病毒引擎(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)卡巴斯基(ji)、賽門鐵(tie)克)和(he)(he)沙箱分(fen)析,檢(jian)測網(wang)(wang)頁(ye)中(zhong)(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)意(yi)(yi)代碼(ma)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) JavaScript 注(zhu)入(ru)、漏洞(dong)利用(yong)工具包(bao)),阻(zu)止(zhi)下(xia)載(zai)惡(e)(e)(e)意(yi)(yi)文件(jian)(jian)(jian)(jian)。
數(shu)(shu)(shu)據(ju)(ju)(ju)防泄露(DLP):掃描上傳(chuan) / 下(xia)載(zai)的(de)(de)(de)(de)文件(jian)(jian)(jian)(jian)內(nei)容(rong),阻(zu)止(zhi)敏感數(shu)(shu)(shu)據(ju)(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)信(xin)(xin)用(yong)卡號、醫(yi)療(liao)記錄(lu)(lu))通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo) Web 表單或文件(jian)(jian)(jian)(jian)傳(chuan)輸泄露,支(zhi)(zhi)持自(zi)定(ding)(ding)義數(shu)(shu)(shu)據(ju)(ju)(ju)指紋(wen)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)正則(ze)表達式(shi)匹配)。
2. 進階(jie)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)力(li)(li)(li)
零(ling)信(xin)(xin)任(ren)(ren)訪(fang)(fang)問(wen)(wen)(wen)控制(zhi)(zhi):基(ji)于 “持續(xu)驗(yan)證(zheng),永(yong)不信(xin)(xin)任(ren)(ren)” 原則(ze),結(jie)合(he)(he)(he)(he)(he)設(she)(she)備(bei)(bei)狀(zhuang)態(tai)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)是(shi)否安(an)(an)(an)(an)(an)(an)裝殺毒軟件(jian)(jian)(jian)(jian))、用(yong)戶(hu)身(shen)份(多(duo)因(yin)素..)和(he)(he)環(huan)境(jing)(jing)(jing)風(feng)險(xian)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)異(yi)常地(di)理(li)位置(zhi)(zhi)登(deng)錄(lu)(lu))動(dong)(dong)(dong)(dong)態(tai)授權訪(fang)(fang)問(wen)(wen)(wen)。
..威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)檢(jian)測:利用(yong)行(xing)(xing)為分(fen)析(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)用(yong)戶(hu)異(yi)常訪(fang)(fang)問(wen)(wen)(wen)模(mo)式(shi))和(he)(he)威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)關(guan)(guan)聯引擎,識別供(gong)應(ying)(ying)鏈攻擊、APT(..持續(xu)性(xing)(xing)(xing)(xing)威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie))等復(fu)雜攻擊鏈。例如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru),檢(jian)測同一(yi)(yi) IP 短時間內(nei)頻繁訪(fang)(fang)問(wen)(wen)(wen)多(duo)個高危站(zhan)點(dian)。
合(he)(he)(he)(he)(he)規性(xing)(xing)(xing)(xing)審計:生(sheng)成(cheng)(cheng)詳細日志報(bao)(bao)告(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)用(yong)戶(hu)訪(fang)(fang)問(wen)(wen)(wen)記錄(lu)(lu)、威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)事件(jian)(jian)(jian)(jian)詳情),滿(man)(man)足(zu) GDPR、等保 2.0、HIPAA 等合(he)(he)(he)(he)(he)規要(yao)求,支(zhi)(zhi)持日志一(yi)(yi)鍵(jian)導出至 SIEM 系(xi)統(tong)。
3. 性(xing)(xing)(xing)(xing)能(neng)(neng)(neng)優(you)(you)化(hua)(hua)功(gong)能(neng)(neng)(neng)
緩(huan)存與(yu)(yu)(yu)(yu)(yu)加(jia)(jia)速:緩(huan)存靜態(tai)內(nei)容(rong)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)圖(tu)片、CSS/JS 文件(jian)(jian)(jian)(jian)),減少重復(fu)下(xia)載(zai),提(ti)升(sheng)網(wang)(wang)頁(ye)加(jia)(jia)載(zai)速度(du)(du)(尤其(qi)適用(yong)于跨(kua)國訪(fang)(fang)問(wen)(wen)(wen)場(chang)景(jing)(jing))。
流(liu)(liu)量(liang)(liang)清洗(xi):通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)端(duan) DDoS 防護(hu)(hu)模(mo)塊(kuai),過(guo)(guo)(guo)(guo)濾(lv)海量(liang)(liang)惡(e)(e)(e)意(yi)(yi)流(liu)(liu)量(liang)(liang)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) SYN Flood、HTTP Flood),保障企(qi)業 Web 服(fu)(fu)(fu)務(wu)(wu)可用(yong)性(xing)(xing)(xing)(xing)。
三(san)、核(he)(he)(he)心(xin)(xin)優(you)(you)勢(shi)與(yu)(yu)(yu)(yu)(yu)適用(yong)場(chang)景(jing)(jing)
1. 優(you)(you)勢(shi)對比(vs 傳(chuan)統(tong)硬(ying)件(jian)(jian)(jian)(jian)網(wang)(wang)關(guan)(guan))
維度(du)(du) 云(yun)(yun)(yun)(yun)(yun)計算 Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan) 傳(chuan)統(tong)硬(ying)件(jian)(jian)(jian)(jian)網(wang)(wang)關(guan)(guan)
部署成(cheng)(cheng)本(ben)(ben) 零(ling)硬(ying)件(jian)(jian)(jian)(jian)投(tou)(tou)入(ru),按(an)(an)需(xu)(xu)(xu)(xu)(xu)付費(OPEX 模(mo)式(shi)) 高初期投(tou)(tou)資(CAPEX),需(xu)(xu)(xu)(xu)(xu)定(ding)(ding)期升(sheng)級(ji)(ji)
擴展性(xing)(xing)(xing)(xing) 彈性(xing)(xing)(xing)(xing)擴展,支(zhi)(zhi)持千(qian)萬級(ji)(ji)并(bing)(bing)發(fa) 受(shou)限(xian)于硬(ying)件(jian)(jian)(jian)(jian)性(xing)(xing)(xing)(xing)能(neng)(neng)(neng),擴容(rong)復(fu)雜
威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)響應(ying)(ying)速度(du)(du) 分(fen)鐘級(ji)(ji)..規則(ze)更新,實(shi)(shi)時威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)情報(bao)(bao)共享(xiang) 依賴手動(dong)(dong)(dong)(dong)更新,區域化(hua)(hua)響應(ying)(ying)延(yan)(yan)遲(chi)
分(fen)布(bu)式(shi)部署 天然支(zhi)(zhi)持多(duo)分(fen)支(zhi)(zhi)機(ji)構(gou)、遠(yuan)程(cheng)辦公(gong)(gong)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)入(ru) 需(xu)(xu)(xu)(xu)(xu)在(zai)(zai)每個節(jie)(jie)點(dian)部署硬(ying)件(jian)(jian)(jian)(jian)設(she)(she)備(bei)(bei)
管理(li)復(fu)雜度(du)(du) 云(yun)(yun)(yun)(yun)(yun)端(duan)統(tong)一(yi)(yi)管理(li),策(ce)(ce)(ce)略(lve)(lve)實(shi)(shi)時生(sheng)效 多(duo)設(she)(she)備(bei)(bei)獨立配置(zhi)(zhi),策(ce)(ce)(ce)略(lve)(lve)同步困難
2. 典型(xing)(xing)(xing)(xing)(xing)應(ying)(ying)用(yong)場(chang)景(jing)(jing)
分(fen)布(bu)式(shi)企(qi)業安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)入(ru):跨(kua)國公(gong)(gong)司分(fen)支(zhi)(zhi)機(ji)構(gou)或遠(yuan)程(cheng)員(yuan)工通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)關(guan)(guan)訪(fang)(fang)問(wen)(wen)(wen)互聯網(wang)(wang),無(wu)需(xu)(xu)(xu)(xu)(xu)在(zai)(zai)每個辦公(gong)(gong)室部署硬(ying)件(jian)(jian)(jian)(jian)設(she)(she)備(bei)(bei),統(tong)一(yi)(yi)策(ce)(ce)(ce)略(lve)(lve)下(xia)發(fa)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)禁止(zhi)訪(fang)(fang)問(wen)(wen)(wen) P2P 下(xia)載(zai)站(zhan)點(dian))。
移(yi)(yi)動(dong)(dong)(dong)(dong)辦公(gong)(gong)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):員(yuan)工通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)手機(ji)、平(ping)板等移(yi)(yi)動(dong)(dong)(dong)(dong)設(she)(she)備(bei)(bei)接(jie)(jie)入(ru)時,云(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)關(guan)(guan)提(ti)供(gong)跨(kua)平(ping)臺(tai)(tai)(tai)的(de)(de)(de)(de)一(yi)(yi)致安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)防護(hu)(hu)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)阻(zu)止(zhi)移(yi)(yi)動(dong)(dong)(dong)(dong)設(she)(she)備(bei)(bei)訪(fang)(fang)問(wen)(wen)(wen)惡(e)(e)(e)意(yi)(yi) APK 下(xia)載(zai)頁(ye)面)。
多(duo)云(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)(jing)(jing)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):企(qi)業使用(yong) AWS、Azure 等多(duo)個云(yun)(yun)(yun)(yun)(yun)平(ping)臺(tai)(tai)(tai)時,云(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)關(guan)(guan)作(zuo)為統(tong)一(yi)(yi)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)入(ru)口(kou),避免不同云(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)(jing)(jing)下(xia)的(de)(de)(de)(de)策(ce)(ce)(ce)略(lve)(lve)孤島(dao)。
中(zhong)(zhong)(zhong)小企(qi)業輕(qing)量(liang)(liang)化(hua)(hua)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):無(wu)需(xu)(xu)(xu)(xu)(xu)專業 IT 團隊(dui)維護(hu)(hu),通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)訂(ding)閱制(zhi)(zhi)獲得企(qi)業級(ji)(ji)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)力(li)(li)(li)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) URL 過(guo)(guo)(guo)(guo)濾(lv)、反惡(e)(e)(e)意(yi)(yi)軟件(jian)(jian)(jian)(jian)),成(cheng)(cheng)本(ben)(ben)僅為硬(ying)件(jian)(jian)(jian)(jian)方案的(de)(de)(de)(de) 1/3~1/2。
四、挑戰與(yu)(yu)(yu)(yu)(yu)風(feng)險(xian)
1. 數(shu)(shu)(shu)據(ju)(ju)(ju)隱(yin)私與(yu)(yu)(yu)(yu)(yu)合(he)(he)(he)(he)(he)規風(feng)險(xian)
用(yong)戶(hu)流(liu)(liu)量(liang)(liang)需(xu)(xu)(xu)(xu)(xu)經第三(san)方云(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)點(dian)處(chu)理(li),可能(neng)(neng)(neng)涉及(ji)(ji)數(shu)(shu)(shu)據(ju)(ju)(ju)跨(kua)境(jing)(jing)(jing)傳(chuan)輸合(he)(he)(he)(he)(he)規問(wen)(wen)(wen)題(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)中(zhong)(zhong)(zhong)國《數(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)法》要(yao)求重要(yao)數(shu)(shu)(shu)據(ju)(ju)(ju)本(ben)(ben)地(di)化(hua)(hua)存儲(chu))。需(xu)(xu)(xu)(xu)(xu)選擇支(zhi)(zhi)持 “區域化(hua)(hua)數(shu)(shu)(shu)據(ju)(ju)(ju)處(chu)理(li)” 的(de)(de)(de)(de)服(fu)(fu)(fu)務(wu)(wu)商(shang)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)在(zai)(zai)本(ben)(ben)地(di)數(shu)(shu)(shu)據(ju)(ju)(ju)中(zhong)(zhong)(zhong)心(xin)(xin)處(chu)理(li)境(jing)(jing)(jing)內(nei)流(liu)(liu)量(liang)(liang))。
云(yun)(yun)(yun)(yun)(yun)端(duan)服(fu)(fu)(fu)務(wu)(wu)商(shang)的(de)(de)(de)(de)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)力(li)(li)(li)直(zhi)接(jie)(jie)影(ying)響用(yong)戶(hu)數(shu)(shu)(shu)據(ju)(ju)(ju)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan),需(xu)(xu)(xu)(xu)(xu)驗(yan)證(zheng)其(qi) ISO 27001、SOC 2 等..,以及(ji)(ji)數(shu)(shu)(shu)據(ju)(ju)(ju)加(jia)(jia)密(mi)(mi)措施(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)傳(chuan)輸層(ceng) TLS 1.3、存儲(chu)層(ceng) AES-256)。
2. 網(wang)(wang)絡(luo)延(yan)(yan)遲(chi)與(yu)(yu)(yu)(yu)(yu)性(xing)(xing)(xing)(xing)能(neng)(neng)(neng)影(ying)響
流(liu)(liu)量(liang)(liang)繞(rao)行(xing)(xing)云(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)點(dian)可能(neng)(neng)(neng)增(zeng)加(jia)(jia)延(yan)(yan)遲(chi)(尤其(qi)用(yong)戶(hu)與(yu)(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)端(duan) POP 距離較遠(yuan)時),需(xu)(xu)(xu)(xu)(xu)服(fu)(fu)(fu)務(wu)(wu)商(shang)通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)邊緣(yuan)計算節(jie)(jie)點(dian)(Edge POP)或 Anycast 技(ji)(ji)術(shu)(shu)優(you)(you)化(hua)(hua)路由(理(li)想情況下(xia)延(yan)(yan)遲(chi)增(zeng)加(jia)(jia) < 5ms)。
SSL 解(jie)密(mi)(mi)可能(neng)(neng)(neng)消耗云(yun)(yun)(yun)(yun)(yun)端(duan)算力(li)(li)(li),需(xu)(xu)(xu)(xu)(xu)關(guan)(guan)注(zhu)服(fu)(fu)(fu)務(wu)(wu)商(shang)的(de)(de)(de)(de)并(bing)(bing)發(fa)處(chu)理(li)能(neng)(neng)(neng)力(li)(li)(li)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)單節(jie)(jie)點(dian)支(zhi)(zhi)持 10Gbps 解(jie)密(mi)(mi)吞吐(tu)量(liang)(liang))。
3. 依賴互聯網(wang)(wang)連接(jie)(jie)
企(qi)業網(wang)(wang)絡(luo)中(zhong)(zhong)(zhong)斷時,云(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)關(guan)(guan)無(wu)法提(ti)供(gong)服(fu)(fu)(fu)務(wu)(wu),需(xu)(xu)(xu)(xu)(xu)結(jie)合(he)(he)(he)(he)(he)本(ben)(ben)地(di)緩(huan)存或備(bei)(bei)用(yong)鏈路(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) SD-WAN)..業務(wu)(wu)連續(xu)性(xing)(xing)(xing)(xing)。
五(wu)、市場(chang)現(xian)狀(zhuang)與(yu)(yu)(yu)(yu)(yu)主(zhu)(zhu)流(liu)(liu)方案
1. 頭部廠(chang)商(shang)與(yu)(yu)(yu)(yu)(yu)產品
Zscaler Internet Access(ZIA):純(chun)云(yun)(yun)(yun)(yun)(yun)端(duan)架(jia)構(gou),主(zhu)(zhu)打(da)(da)零(ling)信(xin)(xin)任(ren)(ren)訪(fang)(fang)問(wen)(wen)(wen),支(zhi)(zhi)持實(shi)(shi)時威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)檢(jian)測與(yu)(yu)(yu)(yu)(yu)數(shu)(shu)(shu)據(ju)(ju)(ju)防泄露,.. POP 節(jie)(jie)點(dian)超 200 個。
Cisco Umbrella:整合(he)(he)(he)(he)(he)域名解(jie)析層(ceng)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)(DNS 過(guo)(guo)(guo)(guo)濾(lv))與(yu)(yu)(yu)(yu)(yu) Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan),通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo) Anycast 網(wang)(wang)絡(luo)降(jiang)低(di)延(yan)(yan)遲(chi),適合(he)(he)(he)(he)(he)混合(he)(he)(he)(he)(he)云(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)(jing)(jing)。
Forcepoint SWG:提(ti)供(gong)深度(du)(du)內(nei)容(rong)檢(jian)測(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)文檔沙箱分(fen)析),支(zhi)(zhi)持自(zi)定(ding)(ding)義策(ce)(ce)(ce)略(lve)(lve)引擎,滿(man)(man)足(zu)金融、政府等高合(he)(he)(he)(he)(he)規需(xu)(xu)(xu)(xu)(xu)求。
Symantec Web Security Service:依托賽門鐵(tie)克..威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)情報(bao)(bao),主(zhu)(zhu)打(da)(da)惡(e)(e)(e)意(yi)(yi)軟件(jian)(jian)(jian)(jian)防護(hu)(hu)與(yu)(yu)(yu)(yu)(yu)合(he)(he)(he)(he)(he)規審計,適合(he)(he)(he)(he)(he)中(zhong)(zhong)(zhong)小企(qi)業。
2. 技(ji)(ji)術(shu)(shu)趨(qu)勢(shi)
與(yu)(yu)(yu)(yu)(yu) SASE(安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)訪(fang)(fang)問(wen)(wen)(wen)服(fu)(fu)(fu)務(wu)(wu)邊緣(yuan))融合(he)(he)(he)(he)(he):Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)作(zuo)為 SASE 架(jia)構(gou)的(de)(de)(de)(de)核(he)(he)(he)心(xin)(xin)組件(jian)(jian)(jian)(jian),與(yu)(yu)(yu)(yu)(yu) SD-WAN、零(ling)信(xin)(xin)任(ren)(ren)網(wang)(wang)絡(luo)訪(fang)(fang)問(wen)(wen)(wen)(ZTNA)等功(gong)能(neng)(neng)(neng)集成(cheng)(cheng),提(ti)供(gong)端(duan)到端(duan)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)入(ru)。
AI 驅(qu)動(dong)(dong)(dong)(dong)的(de)(de)(de)(de)威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)檢(jian)測:利用(yong) NLP 分(fen)析網(wang)(wang)頁(ye)內(nei)容(rong)語(yu)義(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)釣魚郵(you)件(jian)(jian)(jian)(jian)中(zhong)(zhong)(zhong)的(de)(de)(de)(de)社(she)(she)會工程(cheng)話術(shu)(shu)),結(jie)合(he)(he)(he)(he)(he)行(xing)(xing)為分(fen)析模(mo)型(xing)(xing)(xing)(xing)(xing)識別新型(xing)(xing)(xing)(xing)(xing)攻擊。
無(wu)客戶(hu)端(duan)部署:通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)瀏覽器插件(jian)(jian)(jian)(jian)或 API 集成(cheng)(cheng),簡化(hua)(hua)用(yong)戶(hu)接(jie)(jie)入(ru)流(liu)(liu)程(cheng),尤其(qi)適用(yong)于 BYOD(自(zi)帶設(she)(she)備(bei)(bei))場(chang)景(jing)(jing)。
總結(jie)
基(ji)于云(yun)(yun)(yun)(yun)(yun)計算的(de)(de)(de)(de) Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)服(fu)(fu)(fu)務(wu)(wu)通(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)端(duan)化(hua)(hua)、智能(neng)(neng)(neng)化(hua)(hua)和(he)(he)彈性(xing)(xing)(xing)(xing)化(hua)(hua),解(jie)決了傳(chuan)統(tong)硬(ying)件(jian)(jian)(jian)(jian)網(wang)(wang)關(guan)(guan)的(de)(de)(de)(de)部署成(cheng)(cheng)本(ben)(ben)高、擴展性(xing)(xing)(xing)(xing)差等問(wen)(wen)(wen)題,成(cheng)(cheng)為企(qi)業應(ying)(ying)對分(fen)布(bu)式(shi)辦公(gong)(gong)、多(duo)云(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)(jing)(jing)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)的(de)(de)(de)(de)..方案。其(qi)核(he)(he)(he)心(xin)(xin)價值在(zai)(zai)于將(jiang)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)力(li)(li)(li)轉化(hua)(hua)為可按(an)(an)需(xu)(xu)(xu)(xu)(xu)調用(yong)的(de)(de)(de)(de) “安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)即(ji)服(fu)(fu)(fu)務(wu)(wu)”,同時依托..威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)情報(bao)(bao)網(wang)(wang)絡(luo)提(ti)升(sheng)防護(hu)(hu)效率。未(wei)來,隨著 SASE 架(jia)構(gou)的(de)(de)(de)(de)普及(ji)(ji)和(he)(he) AI 技(ji)(ji)術(shu)(shu)的(de)(de)(de)(de)深入(ru)應(ying)(ying)用(yong),該服(fu)(fu)(fu)務(wu)(wu)將(jiang)進一(yi)(yi)步融合(he)(he)(he)(he)(he)網(wang)(wang)絡(luo)與(yu)(yu)(yu)(yu)(yu)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng),為數(shu)(shu)(shu)字化(hua)(hua)轉型(xing)(xing)(xing)(xing)(xing)提(ti)供(gong)更主(zhu)(zhu)動(dong)(dong)(dong)(dong)、更智能(neng)(neng)(neng)的(de)(de)(de)(de)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)保障。企(qi)業在(zai)(zai)選擇時需(xu)(xu)(xu)(xu)(xu)重點(dian)關(guan)(guan)注(zhu)服(fu)(fu)(fu)務(wu)(wu)商(shang)的(de)(de)(de)(de)合(he)(he)(he)(he)(he)規性(xing)(xing)(xing)(xing)、..節(jie)(jie)點(dian)覆蓋及(ji)(ji)威(wei)(wei)(wei)(wei)(wei)(wei)脅(xie)(xie)(xie)響應(ying)(ying)速度(du)(du),平(ping)衡安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)與(yu)(yu)(yu)(yu)(yu)性(xing)(xing)(xing)(xing)能(neng)(neng)(neng)需(xu)(xu)(xu)(xu)(xu)求。一(yi)(yi)、技術(shu)架構與(yu)(yu)(yu)(yu)(yu)(yu)核(he)心(xin)原(yuan)理(li)
1. 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)部(bu)署(shu)模(mo)式
SaaS 化(hua)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu):通(tong)(tong)(tong)(tong)(tong)過(guo)(guo) Web 界面(mian)(mian)或(huo)(huo)(huo) API 提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu),用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)無(wu)需部(bu)署(shu)本(ben)(ben)地(di)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian),直接(jie)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)互聯(lian)(lian)(lian)網(wang)(wang)(wang)(wang)接(jie)入(ru)(ru)(ru)(ru)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)安(an)(an)(an)(an)..關(guan)(guan)(如(ru)(ru)(ru) Zscaler、Cisco Umbrella 等(deng)(deng)(deng))。
分(fen)(fen)(fen)(fen)布式節(jie)(jie)(jie)點(dian)覆蓋:在(zai)(zai)..多(duo)(duo)個數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)中心(xin)部(bu)署(shu) POP(接(jie)入(ru)(ru)(ru)(ru)點(dian)),用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)流(liu)(liu)量就近接(jie)入(ru)(ru)(ru)(ru)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)節(jie)(jie)(jie)點(dian),經安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)檢(jian)(jian)測(ce)(ce)(ce)(ce)后(hou)轉(zhuan)(zhuan)發(fa)至(zhi)(zhi)目標網(wang)(wang)(wang)(wang)站(zhan)(zhan),降(jiang)低延遲(chi)(chi)(chi)(如(ru)(ru)(ru)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo) Anycast 技術(shu)優(you)化(hua)路由)。
與(yu)(yu)(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)基礎設施集(ji)(ji)成(cheng)(cheng):無(wu)縫(feng)對接(jie) AWS、Azure、阿(a)里(li)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)等(deng)(deng)(deng)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)平臺,支(zhi)持(chi)(chi)混合(he)(he)(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun) / 多(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)下(xia)的(de)(de)(de)(de)(de)(de)(de)統(tong)(tong)(tong)一(yi)(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)策(ce)略。
2. 核(he)心(xin)技術(shu)支(zhi)撐
威(wei)脅(xie)(xie)(xie)(xie)情(qing)報(bao)共(gong)享(xiang):云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)匯聚..用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)的(de)(de)(de)(de)(de)(de)(de)威(wei)脅(xie)(xie)(xie)(xie)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)(如(ru)(ru)(ru)惡意(yi)(yi) URL、釣魚頁(ye)面(mian)(mian)、勒索軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)特征),通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)機器學習實(shi)時(shi)(shi)(shi)(shi)更(geng)(geng)新(xin)檢(jian)(jian)測(ce)(ce)(ce)(ce)模(mo)型,提(ti)(ti)(ti)(ti)(ti)升(sheng)零(ling)日(ri)攻(gong)擊識(shi)別能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力。
SSL/TLS 解(jie)(jie)密與(yu)(yu)(yu)(yu)(yu)(yu)檢(jian)(jian)測(ce)(ce)(ce)(ce):在(zai)(zai)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)對加(jia)密流(liu)(liu)量(HTTPS)進(jin)行(xing)解(jie)(jie)密分(fen)(fen)(fen)(fen)析(xi)(xi),檢(jian)(jian)測(ce)(ce)(ce)(ce)隱(yin)藏在(zai)(zai)加(jia)密通(tong)(tong)(tong)(tong)(tong)道中的(de)(de)(de)(de)(de)(de)(de)惡意(yi)(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)或(huo)(huo)(huo)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)泄(xie)(xie)露行(xing)為(wei)(wei)(wei)(需用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)授權證書)。
API 驅動(dong)(dong)的(de)(de)(de)(de)(de)(de)(de)策(ce)略引擎(qing):通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)開放 API 接(jie)口(kou),企(qi)業(ye)可自(zi)定義(yi)(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)策(ce)略(如(ru)(ru)(ru)按(an)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)角(jiao)色、設備(bei)類型、地(di)理(li)位置限制訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)),并(bing)與(yu)(yu)(yu)(yu)(yu)(yu)現有 IT 系(xi)統(tong)(tong)(tong)(如(ru)(ru)(ru) AD、SIEM)聯(lian)(lian)(lian)動(dong)(dong)。
二、核(he)心(xin)功(gong)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)與(yu)(yu)(yu)(yu)(yu)(yu)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力
1. 基礎安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)
URL 過(guo)(guo)濾(lv)與(yu)(yu)(yu)(yu)(yu)(yu)內(nei)容(rong)(rong)審(shen)(shen)查:根(gen)據(ju)(ju)(ju)(ju)(ju)預定義(yi)(yi)規(gui)(gui)(gui)則(如(ru)(ru)(ru)行(xing)業(ye)合(he)(he)(he)規(gui)(gui)(gui)要(yao)求(qiu)、企(qi)業(ye)風(feng)(feng)險(xian)偏(pian)好),攔截惡意(yi)(yi)或(huo)(huo)(huo)違規(gui)(gui)(gui) URL(如(ru)(ru)(ru)賭博、釣魚網(wang)(wang)(wang)(wang)站(zhan)(zhan)),支(zhi)持(chi)(chi)細粒(li)度分(fen)(fen)(fen)(fen)類(如(ru)(ru)(ru) “社交(jiao)網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo) - 工(gong)(gong)作(zuo)相關(guan)(guan)”“文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)共(gong)享(xiang) - 高(gao)(gao)風(feng)(feng)險(xian)”)。
惡意(yi)(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)防(fang)(fang)(fang)護(hu):通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)反(fan)病毒(du)(du)引擎(qing)(如(ru)(ru)(ru)卡巴(ba)斯基、賽(sai)門鐵克)和(he)沙箱分(fen)(fen)(fen)(fen)析(xi)(xi),檢(jian)(jian)測(ce)(ce)(ce)(ce)網(wang)(wang)(wang)(wang)頁(ye)中的(de)(de)(de)(de)(de)(de)(de)惡意(yi)(yi)代碼(如(ru)(ru)(ru) JavaScript 注入(ru)(ru)(ru)(ru)、漏洞利用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)工(gong)(gong)具包),阻(zu)止(zhi)下(xia)載(zai)(zai)惡意(yi)(yi)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)。
數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)防(fang)(fang)(fang)泄(xie)(xie)露(DLP):掃描上傳(chuan)(chuan) / 下(xia)載(zai)(zai)的(de)(de)(de)(de)(de)(de)(de)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)內(nei)容(rong)(rong),阻(zu)止(zhi)敏感數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)(如(ru)(ru)(ru)信用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)卡號、醫療(liao)記(ji)錄(lu))通(tong)(tong)(tong)(tong)(tong)過(guo)(guo) Web 表單或(huo)(huo)(huo)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)傳(chuan)(chuan)輸(shu)泄(xie)(xie)露,支(zhi)持(chi)(chi)自(zi)定義(yi)(yi)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)指紋(如(ru)(ru)(ru)正則表達式匹配)。
2. 進(jin)階(jie)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力
零(ling)信任(ren)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)控制:基于(yu) “持(chi)(chi)續驗證,永(yong)不信任(ren)” 原(yuan)則,結合(he)(he)(he)設備(bei)狀(zhuang)(zhuang)態(如(ru)(ru)(ru)是否安(an)(an)(an)(an)裝(zhuang)殺毒(du)(du)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian))、用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)身(shen)份(fen)(多(duo)(duo)因素..)和(he)環(huan)境(jing)風(feng)(feng)險(xian)(如(ru)(ru)(ru)異常地(di)理(li)位置登(deng)錄(lu))動(dong)(dong)態授權訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)。
..威(wei)脅(xie)(xie)(xie)(xie)檢(jian)(jian)測(ce)(ce)(ce)(ce):利用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)行(xing)為(wei)(wei)(wei)分(fen)(fen)(fen)(fen)析(xi)(xi)(如(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)異常訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)模(mo)式)和(he)威(wei)脅(xie)(xie)(xie)(xie)關(guan)(guan)聯(lian)(lian)(lian)引擎(qing),識(shi)別供(gong)(gong)(gong)應(ying)(ying)鏈攻(gong)擊、APT(..持(chi)(chi)續性(xing)(xing)威(wei)脅(xie)(xie)(xie)(xie))等(deng)(deng)(deng)復(fu)(fu)雜攻(gong)擊鏈。例如(ru)(ru)(ru),檢(jian)(jian)測(ce)(ce)(ce)(ce)同(tong)一(yi)(yi) IP 短時(shi)(shi)(shi)(shi)間內(nei)頻繁(fan)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)多(duo)(duo)個高(gao)(gao)危站(zhan)(zhan)點(dian)。
合(he)(he)(he)規(gui)(gui)(gui)性(xing)(xing)審(shen)(shen)計(ji):生成(cheng)(cheng)詳(xiang)細日(ri)志(zhi)報(bao)告(如(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)記(ji)錄(lu)、威(wei)脅(xie)(xie)(xie)(xie)事件(jian)(jian)(jian)(jian)(jian)(jian)詳(xiang)情(qing)),滿(man)足 GDPR、等(deng)(deng)(deng)保(bao) 2.0、HIPAA 等(deng)(deng)(deng)合(he)(he)(he)規(gui)(gui)(gui)要(yao)求(qiu),支(zhi)持(chi)(chi)日(ri)志(zhi)一(yi)(yi)鍵導出至(zhi)(zhi) SIEM 系(xi)統(tong)(tong)(tong)。
3. 性(xing)(xing)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)優(you)化(hua)功(gong)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)
緩存(cun)與(yu)(yu)(yu)(yu)(yu)(yu)加(jia)速:緩存(cun)靜態內(nei)容(rong)(rong)(如(ru)(ru)(ru)圖片、CSS/JS 文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)),減少重復(fu)(fu)下(xia)載(zai)(zai),提(ti)(ti)(ti)(ti)(ti)升(sheng)網(wang)(wang)(wang)(wang)頁(ye)加(jia)載(zai)(zai)速度(尤其(qi)(qi)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)于(yu)跨國訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)場(chang)景)。
流(liu)(liu)量清(qing)洗:通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan) DDoS 防(fang)(fang)(fang)護(hu)模(mo)塊,過(guo)(guo)濾(lv)海(hai)量惡意(yi)(yi)流(liu)(liu)量(如(ru)(ru)(ru) SYN Flood、HTTP Flood),保(bao)障企(qi)業(ye) Web 服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)可用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)性(xing)(xing)。
三、核(he)心(xin)優(you)勢(shi)與(yu)(yu)(yu)(yu)(yu)(yu)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)場(chang)景
1. 優(you)勢(shi)對比(vs 傳(chuan)(chuan)統(tong)(tong)(tong)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)關(guan)(guan))
維(wei)度 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)算 Web 安(an)(an)(an)(an)..關(guan)(guan) 傳(chuan)(chuan)統(tong)(tong)(tong)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)關(guan)(guan)
部(bu)署(shu)成(cheng)(cheng)本(ben)(ben) 零(ling)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)投入(ru)(ru)(ru)(ru),按(an)需付費(OPEX 模(mo)式) 高(gao)(gao)初期(qi)投資(zi)(CAPEX),需定期(qi)升(sheng)級
擴(kuo)展性(xing)(xing) 彈(dan)性(xing)(xing)擴(kuo)展,支(zhi)持(chi)(chi)千(qian)萬級并(bing)發(fa) 受限于(yu)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)性(xing)(xing)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng),擴(kuo)容(rong)(rong)復(fu)(fu)雜
威(wei)脅(xie)(xie)(xie)(xie)響(xiang)(xiang)應(ying)(ying)速度 分(fen)(fen)(fen)(fen)鐘級..規(gui)(gui)(gui)則更(geng)(geng)新(xin),實(shi)時(shi)(shi)(shi)(shi)威(wei)脅(xie)(xie)(xie)(xie)情(qing)報(bao)共(gong)享(xiang) 依賴(lai)手(shou)動(dong)(dong)更(geng)(geng)新(xin),區域(yu)化(hua)響(xiang)(xiang)應(ying)(ying)延遲(chi)(chi)(chi)
分(fen)(fen)(fen)(fen)布式部(bu)署(shu) 天然支(zhi)持(chi)(chi)多(duo)(duo)分(fen)(fen)(fen)(fen)支(zhi)機構、遠程辦公(gong)(gong)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)入(ru)(ru)(ru)(ru) 需在(zai)(zai)每個節(jie)(jie)(jie)點(dian)部(bu)署(shu)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)設備(bei)
管理(li)復(fu)(fu)雜度 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)統(tong)(tong)(tong)一(yi)(yi)管理(li),策(ce)略實(shi)時(shi)(shi)(shi)(shi)生效 多(duo)(duo)設備(bei)獨立(li)配置,策(ce)略同(tong)步困難
2. 典型應(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)場(chang)景
分(fen)(fen)(fen)(fen)布式企(qi)業(ye)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)入(ru)(ru)(ru)(ru):跨國公(gong)(gong)司(si)分(fen)(fen)(fen)(fen)支(zhi)機構或(huo)(huo)(huo)遠程員工(gong)(gong)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)網(wang)(wang)(wang)(wang)關(guan)(guan)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)互聯(lian)(lian)(lian)網(wang)(wang)(wang)(wang),無(wu)需在(zai)(zai)每個辦公(gong)(gong)室(shi)部(bu)署(shu)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)設備(bei),統(tong)(tong)(tong)一(yi)(yi)策(ce)略下(xia)發(fa)(如(ru)(ru)(ru)禁止(zhi)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen) P2P 下(xia)載(zai)(zai)站(zhan)(zhan)點(dian))。
移(yi)動(dong)(dong)辦公(gong)(gong)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):員工(gong)(gong)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)手(shou)機、平板(ban)等(deng)(deng)(deng)移(yi)動(dong)(dong)設備(bei)接(jie)入(ru)(ru)(ru)(ru)時(shi)(shi)(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)網(wang)(wang)(wang)(wang)關(guan)(guan)提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)跨平臺的(de)(de)(de)(de)(de)(de)(de)一(yi)(yi)致安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)防(fang)(fang)(fang)護(hu)(如(ru)(ru)(ru)阻(zu)止(zhi)移(yi)動(dong)(dong)設備(bei)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)惡意(yi)(yi) APK 下(xia)載(zai)(zai)頁(ye)面(mian)(mian))。
多(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):企(qi)業(ye)使(shi)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong) AWS、Azure 等(deng)(deng)(deng)多(duo)(duo)個云(yun)(yun)(yun)(yun)(yun)(yun)(yun)平臺時(shi)(shi)(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)網(wang)(wang)(wang)(wang)關(guan)(guan)作(zuo)為(wei)(wei)(wei)統(tong)(tong)(tong)一(yi)(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)入(ru)(ru)(ru)(ru)口(kou),避免不同(tong)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)下(xia)的(de)(de)(de)(de)(de)(de)(de)策(ce)略孤島。
中小企(qi)業(ye)輕(qing)量化(hua)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):無(wu)需專業(ye) IT 團隊維(wei)護(hu),通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)訂閱制獲得企(qi)業(ye)級安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力(如(ru)(ru)(ru) URL 過(guo)(guo)濾(lv)、反(fan)惡意(yi)(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)),成(cheng)(cheng)本(ben)(ben)僅為(wei)(wei)(wei)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)方案的(de)(de)(de)(de)(de)(de)(de) 1/3~1/2。
四(si)、挑戰與(yu)(yu)(yu)(yu)(yu)(yu)風(feng)(feng)險(xian)
1. 數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)隱(yin)私與(yu)(yu)(yu)(yu)(yu)(yu)合(he)(he)(he)規(gui)(gui)(gui)風(feng)(feng)險(xian)
用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)流(liu)(liu)量需經第三方云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)節(jie)(jie)(jie)點(dian)處(chu)理(li),可能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)涉及數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)跨境(jing)傳(chuan)(chuan)輸(shu)合(he)(he)(he)規(gui)(gui)(gui)問(wen)(wen)(wen)(wen)題(如(ru)(ru)(ru)中國《數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)法》要(yao)求(qiu)重要(yao)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)本(ben)(ben)地(di)化(hua)存(cun)儲)。需選(xuan)擇(ze)支(zhi)持(chi)(chi) “區域(yu)化(hua)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)處(chu)理(li)” 的(de)(de)(de)(de)(de)(de)(de)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)商(shang)(如(ru)(ru)(ru)在(zai)(zai)本(ben)(ben)地(di)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)中心(xin)處(chu)理(li)境(jing)內(nei)流(liu)(liu)量)。
云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)商(shang)的(de)(de)(de)(de)(de)(de)(de)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力直接(jie)影響(xiang)(xiang)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan),需驗證其(qi)(qi) ISO 27001、SOC 2 等(deng)(deng)(deng)..,以及數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)加(jia)密措施(如(ru)(ru)(ru)傳(chuan)(chuan)輸(shu)層 TLS 1.3、存(cun)儲層 AES-256)。
2. 網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)延遲(chi)(chi)(chi)與(yu)(yu)(yu)(yu)(yu)(yu)性(xing)(xing)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)影響(xiang)(xiang)
流(liu)(liu)量繞行(xing)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)節(jie)(jie)(jie)點(dian)可能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)增加(jia)延遲(chi)(chi)(chi)(尤其(qi)(qi)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)與(yu)(yu)(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan) POP 距離較遠時(shi)(shi)(shi)(shi)),需服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)商(shang)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)邊緣(yuan)計(ji)算節(jie)(jie)(jie)點(dian)(Edge POP)或(huo)(huo)(huo) Anycast 技術(shu)優(you)化(hua)路由(理(li)想情(qing)況下(xia)延遲(chi)(chi)(chi)增加(jia) < 5ms)。
SSL 解(jie)(jie)密可能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)消(xiao)耗云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)算力,需關(guan)(guan)注服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)商(shang)的(de)(de)(de)(de)(de)(de)(de)并(bing)發(fa)處(chu)理(li)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力(如(ru)(ru)(ru)單節(jie)(jie)(jie)點(dian)支(zhi)持(chi)(chi) 10Gbps 解(jie)(jie)密吞吐(tu)量)。
3. 依賴(lai)互聯(lian)(lian)(lian)網(wang)(wang)(wang)(wang)連接(jie)
企(qi)業(ye)網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)中斷時(shi)(shi)(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)網(wang)(wang)(wang)(wang)關(guan)(guan)無(wu)法提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu),需結合(he)(he)(he)本(ben)(ben)地(di)緩存(cun)或(huo)(huo)(huo)備(bei)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)鏈路(如(ru)(ru)(ru) SD-WAN)..業(ye)務(wu)(wu)(wu)(wu)連續性(xing)(xing)。
五(wu)、市場(chang)現狀(zhuang)(zhuang)與(yu)(yu)(yu)(yu)(yu)(yu)主(zhu)流(liu)(liu)方案
1. 頭部(bu)廠(chang)商(shang)與(yu)(yu)(yu)(yu)(yu)(yu)產品
Zscaler Internet Access(ZIA):純云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)架構,主(zhu)打零(ling)信任(ren)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen),支(zhi)持(chi)(chi)實(shi)時(shi)(shi)(shi)(shi)威(wei)脅(xie)(xie)(xie)(xie)檢(jian)(jian)測(ce)(ce)(ce)(ce)與(yu)(yu)(yu)(yu)(yu)(yu)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)防(fang)(fang)(fang)泄(xie)(xie)露,.. POP 節(jie)(jie)(jie)點(dian)超 200 個。
Cisco Umbrella:整合(he)(he)(he)域(yu)名解(jie)(jie)析(xi)(xi)層安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(DNS 過(guo)(guo)濾(lv))與(yu)(yu)(yu)(yu)(yu)(yu) Web 安(an)(an)(an)(an)..關(guan)(guan),通(tong)(tong)(tong)(tong)(tong)過(guo)(guo) Anycast 網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)降(jiang)低延遲(chi)(chi)(chi),適(shi)(shi)合(he)(he)(he)混合(he)(he)(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)。
Forcepoint SWG:提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)深度內(nei)容(rong)(rong)檢(jian)(jian)測(ce)(ce)(ce)(ce)(如(ru)(ru)(ru)文(wen)檔沙箱分(fen)(fen)(fen)(fen)析(xi)(xi)),支(zhi)持(chi)(chi)自(zi)定義(yi)(yi)策(ce)略引擎(qing),滿(man)足金融、政府等(deng)(deng)(deng)高(gao)(gao)合(he)(he)(he)規(gui)(gui)(gui)需求(qiu)。
Symantec Web Security Service:依托賽(sai)門鐵克..威(wei)脅(xie)(xie)(xie)(xie)情(qing)報(bao),主(zhu)打惡意(yi)(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)防(fang)(fang)(fang)護(hu)與(yu)(yu)(yu)(yu)(yu)(yu)合(he)(he)(he)規(gui)(gui)(gui)審(shen)(shen)計(ji),適(shi)(shi)合(he)(he)(he)中小企(qi)業(ye)。
2. 技術(shu)趨勢(shi)
與(yu)(yu)(yu)(yu)(yu)(yu) SASE(安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)邊緣(yuan))融合(he)(he)(he):Web 安(an)(an)(an)(an)..關(guan)(guan)作(zuo)為(wei)(wei)(wei) SASE 架構的(de)(de)(de)(de)(de)(de)(de)核(he)心(xin)組件(jian)(jian)(jian)(jian)(jian)(jian),與(yu)(yu)(yu)(yu)(yu)(yu) SD-WAN、零(ling)信任(ren)網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)訪(fang)(fang)(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(wen)(ZTNA)等(deng)(deng)(deng)功(gong)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)集(ji)(ji)成(cheng)(cheng),提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)到(dao)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)入(ru)(ru)(ru)(ru)。
AI 驅動(dong)(dong)的(de)(de)(de)(de)(de)(de)(de)威(wei)脅(xie)(xie)(xie)(xie)檢(jian)(jian)測(ce)(ce)(ce)(ce):利用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong) NLP 分(fen)(fen)(fen)(fen)析(xi)(xi)網(wang)(wang)(wang)(wang)頁(ye)內(nei)容(rong)(rong)語義(yi)(yi)(如(ru)(ru)(ru)釣魚郵件(jian)(jian)(jian)(jian)(jian)(jian)中的(de)(de)(de)(de)(de)(de)(de)社會工(gong)(gong)程話術(shu)),結合(he)(he)(he)行(xing)為(wei)(wei)(wei)分(fen)(fen)(fen)(fen)析(xi)(xi)模(mo)型識(shi)別新(xin)型攻(gong)擊。
無(wu)客戶(hu)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)部(bu)署(shu):通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)瀏覽(lan)器插件(jian)(jian)(jian)(jian)(jian)(jian)或(huo)(huo)(huo) API 集(ji)(ji)成(cheng)(cheng),簡化(hua)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)接(jie)入(ru)(ru)(ru)(ru)流(liu)(liu)程,尤其(qi)(qi)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)于(yu) BYOD(自(zi)帶設備(bei))場(chang)景。
總結
基于(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)算的(de)(de)(de)(de)(de)(de)(de) Web 安(an)(an)(an)(an)..關(guan)(guan)服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)通(tong)(tong)(tong)(tong)(tong)過(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)(duan)(duan)(duan)(duan)(duan)化(hua)、智(zhi)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)化(hua)和(he)彈(dan)性(xing)(xing)化(hua),解(jie)(jie)決了傳(chuan)(chuan)統(tong)(tong)(tong)硬(ying)(ying)(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)關(guan)(guan)的(de)(de)(de)(de)(de)(de)(de)部(bu)署(shu)成(cheng)(cheng)本(ben)(ben)高(gao)(gao)、擴(kuo)展性(xing)(xing)差等(deng)(deng)(deng)問(wen)(wen)(wen)(wen)題,成(cheng)(cheng)為(wei)(wei)(wei)企(qi)業(ye)應(ying)(ying)對分(fen)(fen)(fen)(fen)布式辦公(gong)(gong)、多(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)境(jing)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)的(de)(de)(de)(de)(de)(de)(de)..方案。其(qi)(qi)核(he)心(xin)價值在(zai)(zai)于(yu)將安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)力轉(zhuan)(zhuan)化(hua)為(wei)(wei)(wei)可按(an)需調(diao)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)的(de)(de)(de)(de)(de)(de)(de) “安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)即服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)”,同(tong)時(shi)(shi)(shi)(shi)依托..威(wei)脅(xie)(xie)(xie)(xie)情(qing)報(bao)網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)提(ti)(ti)(ti)(ti)(ti)升(sheng)防(fang)(fang)(fang)護(hu)效率(lv)。未來,隨著 SASE 架構的(de)(de)(de)(de)(de)(de)(de)普及和(he) AI 技術(shu)的(de)(de)(de)(de)(de)(de)(de)深入(ru)(ru)(ru)(ru)應(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong)(yong),該服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)將進(jin)一(yi)(yi)步融合(he)(he)(he)網(wang)(wang)(wang)(wang)絡(luo)(luo)(luo)與(yu)(yu)(yu)(yu)(yu)(yu)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng),為(wei)(wei)(wei)數(shu)(shu)(shu)字(zi)化(hua)轉(zhuan)(zhuan)型提(ti)(ti)(ti)(ti)(ti)供(gong)(gong)(gong)更(geng)(geng)主(zhu)動(dong)(dong)、更(geng)(geng)智(zhi)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)的(de)(de)(de)(de)(de)(de)(de)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)保(bao)障。企(qi)業(ye)在(zai)(zai)選(xuan)擇(ze)時(shi)(shi)(shi)(shi)需重點(dian)關(guan)(guan)注服(fu)(fu)(fu)務(wu)(wu)(wu)(wu)商(shang)的(de)(de)(de)(de)(de)(de)(de)合(he)(he)(he)規(gui)(gui)(gui)性(xing)(xing)、..節(jie)(jie)(jie)點(dian)覆蓋及威(wei)脅(xie)(xie)(xie)(xie)響(xiang)(xiang)應(ying)(ying)速度,平衡安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)與(yu)(yu)(yu)(yu)(yu)(yu)性(xing)(xing)能(neng)(neng)(neng)(neng)(neng)(neng)(neng)(neng)需求(qiu)。一(yi)、技(ji)術(shu)架(jia)(jia)構(gou)(gou)與(yu)(yu)(yu)(yu)核(he)(he)心(xin)(xin)(xin)原理(li)(li)(li)(li)
1. 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)部(bu)(bu)(bu)署(shu)模(mo)式(shi)
SaaS 化(hua)(hua)服(fu)務(wu):通(tong)(tong)過(guo)(guo)(guo)(guo)(guo) Web 界面(mian)或(huo) API 提(ti)(ti)供(gong)(gong)(gong)服(fu)務(wu),用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)無(wu)(wu)需(xu)(xu)(xu)(xu)(xu)(xu)部(bu)(bu)(bu)署(shu)本(ben)(ben)地(di)(di)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian),直接(jie)(jie)(jie)(jie)(jie)通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)互(hu)(hu)聯(lian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)安(an)(an)(an)(an)..關(guan)(guan)(如(ru)(ru)(ru)(ru)(ru) Zscaler、Cisco Umbrella 等(deng))。
分(fen)(fen)(fen)(fen)布(bu)(bu)式(shi)節(jie)點(dian)覆蓋:在..多(duo)(duo)(duo)個(ge)(ge)數(shu)(shu)(shu)據(ju)(ju)中(zhong)(zhong)心(xin)(xin)(xin)部(bu)(bu)(bu)署(shu) POP(接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)點(dian)),用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)流(liu)(liu)(liu)量(liang)就近接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)節(jie)點(dian),經(jing)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)檢(jian)測(ce)(ce)后轉發(fa)至目(mu)標網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)站,降低延(yan)(yan)遲(chi)(如(ru)(ru)(ru)(ru)(ru)通(tong)(tong)過(guo)(guo)(guo)(guo)(guo) Anycast 技(ji)術(shu)優(you)(you)(you)化(hua)(hua)路由)。
與(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)基礎(chu)設(she)(she)(she)施(shi)集成(cheng)(cheng):無(wu)(wu)縫對(dui)接(jie)(jie)(jie)(jie)(jie) AWS、Azure、阿里云(yun)(yun)(yun)(yun)(yun)(yun)(yun)等(deng)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)平臺,支(zhi)持(chi)(chi)混(hun)合(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun) / 多(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環境(jing)下的(de)(de)(de)(de)統(tong)(tong)一(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)策(ce)略。
2. 核(he)(he)心(xin)(xin)(xin)技(ji)術(shu)支(zhi)撐
威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)情(qing)(qing)報(bao)(bao)共(gong)享(xiang):云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)匯聚..用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)的(de)(de)(de)(de)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)數(shu)(shu)(shu)據(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)惡(e)(e)(e)(e)意(yi) URL、釣魚頁(ye)(ye)面(mian)、勒索(suo)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)特征),通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)機器學習實(shi)時(shi)(shi)更(geng)新(xin)(xin)檢(jian)測(ce)(ce)模(mo)型,提(ti)(ti)升零日攻(gong)(gong)擊識別(bie)能(neng)(neng)(neng)(neng)(neng)力(li)。
SSL/TLS 解密(mi)與(yu)(yu)(yu)(yu)檢(jian)測(ce)(ce):在云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)對(dui)加(jia)(jia)密(mi)流(liu)(liu)(liu)量(liang)(HTTPS)進(jin)行解密(mi)分(fen)(fen)(fen)(fen)析(xi),檢(jian)測(ce)(ce)隱藏在加(jia)(jia)密(mi)通(tong)(tong)道中(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)或(huo)數(shu)(shu)(shu)據(ju)(ju)泄(xie)(xie)露(lu)行為(wei)(需(xu)(xu)(xu)(xu)(xu)(xu)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)授(shou)(shou)權證書(shu))。
API 驅(qu)動(dong)(dong)(dong)(dong)(dong)的(de)(de)(de)(de)策(ce)略引(yin)(yin)擎(qing):通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)開放(fang) API 接(jie)(jie)(jie)(jie)(jie)口(kou)(kou),企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)可自定(ding)義(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)策(ce)略(如(ru)(ru)(ru)(ru)(ru)按用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)角(jiao)色(se)、設(she)(she)(she)備(bei)(bei)(bei)類型、地(di)(di)理(li)(li)(li)(li)位(wei)置限(xian)(xian)制(zhi)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)),并(bing)與(yu)(yu)(yu)(yu)現有 IT 系(xi)統(tong)(tong)(如(ru)(ru)(ru)(ru)(ru) AD、SIEM)聯(lian)動(dong)(dong)(dong)(dong)(dong)。
二、核(he)(he)心(xin)(xin)(xin)功(gong)能(neng)(neng)(neng)(neng)(neng)與(yu)(yu)(yu)(yu)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)力(li)
1. 基礎(chu)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng)(neng)
URL 過(guo)(guo)(guo)(guo)(guo)濾與(yu)(yu)(yu)(yu)內容審查:根(gen)據(ju)(ju)預定(ding)義(yi)規(gui)(gui)(gui)則(ze)(ze)(如(ru)(ru)(ru)(ru)(ru)行業(ye)(ye)(ye)(ye)(ye)(ye)(ye)合(he)規(gui)(gui)(gui)要求、企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)風(feng)(feng)險(xian)偏好),攔截惡(e)(e)(e)(e)意(yi)或(huo)違(wei)規(gui)(gui)(gui) URL(如(ru)(ru)(ru)(ru)(ru)賭(du)博、釣魚網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)站),支(zhi)持(chi)(chi)細(xi)粒度(du)分(fen)(fen)(fen)(fen)類(如(ru)(ru)(ru)(ru)(ru) “社交(jiao)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo) - 工(gong)作相(xiang)關(guan)(guan)”“文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)共(gong)享(xiang) - 高(gao)(gao)風(feng)(feng)險(xian)”)。
惡(e)(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)防(fang)護(hu)(hu):通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)反(fan)病毒引(yin)(yin)擎(qing)(如(ru)(ru)(ru)(ru)(ru)卡巴斯基、賽門鐵克)和(he)沙箱分(fen)(fen)(fen)(fen)析(xi),檢(jian)測(ce)(ce)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)頁(ye)(ye)中(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)(e)意(yi)代碼(ma)(如(ru)(ru)(ru)(ru)(ru) JavaScript 注入(ru)(ru)(ru)、漏洞利用(yong)(yong)(yong)(yong)(yong)(yong)工(gong)具包),阻(zu)(zu)止(zhi)(zhi)下載(zai)(zai)惡(e)(e)(e)(e)意(yi)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)。
數(shu)(shu)(shu)據(ju)(ju)防(fang)泄(xie)(xie)露(lu)(DLP):掃描上傳(chuan) / 下載(zai)(zai)的(de)(de)(de)(de)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)內容,阻(zu)(zu)止(zhi)(zhi)敏感數(shu)(shu)(shu)據(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)信(xin)用(yong)(yong)(yong)(yong)(yong)(yong)卡號、醫療記錄(lu))通(tong)(tong)過(guo)(guo)(guo)(guo)(guo) Web 表單(dan)或(huo)文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)傳(chuan)輸(shu)泄(xie)(xie)露(lu),支(zhi)持(chi)(chi)自定(ding)義(yi)數(shu)(shu)(shu)據(ju)(ju)指紋(如(ru)(ru)(ru)(ru)(ru)正則(ze)(ze)表達式(shi)匹配)。
2. 進(jin)階安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)力(li)
零信(xin)任訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)控制(zhi):基于 “持(chi)(chi)續(xu)(xu)驗(yan)證,永不(bu)(bu)信(xin)任” 原則(ze)(ze),結(jie)合(he)設(she)(she)(she)備(bei)(bei)(bei)狀態(tai)(tai)(如(ru)(ru)(ru)(ru)(ru)是否安(an)(an)(an)(an)裝(zhuang)殺毒軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian))、用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)身份(多(duo)(duo)(duo)因素..)和(he)環境(jing)風(feng)(feng)險(xian)(如(ru)(ru)(ru)(ru)(ru)異(yi)常地(di)(di)理(li)(li)(li)(li)位(wei)置登錄(lu))動(dong)(dong)(dong)(dong)(dong)態(tai)(tai)授(shou)(shou)權訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)。
..威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)檢(jian)測(ce)(ce):利用(yong)(yong)(yong)(yong)(yong)(yong)行為(wei)分(fen)(fen)(fen)(fen)析(xi)(如(ru)(ru)(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)異(yi)常訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)模(mo)式(shi))和(he)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)關(guan)(guan)聯(lian)引(yin)(yin)擎(qing),識別(bie)供(gong)(gong)(gong)應(ying)(ying)鏈(lian)攻(gong)(gong)擊、APT(..持(chi)(chi)續(xu)(xu)性(xing)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie))等(deng)復(fu)雜攻(gong)(gong)擊鏈(lian)。例如(ru)(ru)(ru)(ru)(ru),檢(jian)測(ce)(ce)同(tong)一(yi) IP 短時(shi)(shi)間內頻繁訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)多(duo)(duo)(duo)個(ge)(ge)高(gao)(gao)危站點(dian)。
合(he)規(gui)(gui)(gui)性(xing)審計(ji):生成(cheng)(cheng)詳細(xi)日志(zhi)報(bao)(bao)告(gao)(如(ru)(ru)(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)記錄(lu)、威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)事件(jian)(jian)(jian)(jian)(jian)(jian)(jian)詳情(qing)(qing)),滿足 GDPR、等(deng)保 2.0、HIPAA 等(deng)合(he)規(gui)(gui)(gui)要求,支(zhi)持(chi)(chi)日志(zhi)一(yi)鍵導出至 SIEM 系(xi)統(tong)(tong)。
3. 性(xing)能(neng)(neng)(neng)(neng)(neng)優(you)(you)(you)化(hua)(hua)功(gong)能(neng)(neng)(neng)(neng)(neng)
緩(huan)(huan)存(cun)與(yu)(yu)(yu)(yu)加(jia)(jia)速(su):緩(huan)(huan)存(cun)靜態(tai)(tai)內容(如(ru)(ru)(ru)(ru)(ru)圖(tu)片、CSS/JS 文(wen)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)),減少重復(fu)下載(zai)(zai),提(ti)(ti)升網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)頁(ye)(ye)加(jia)(jia)載(zai)(zai)速(su)度(du)(尤(you)(you)其適(shi)用(yong)(yong)(yong)(yong)(yong)(yong)于跨(kua)國訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)場景(jing))。
流(liu)(liu)(liu)量(liang)清洗:通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan) DDoS 防(fang)護(hu)(hu)模(mo)塊,過(guo)(guo)(guo)(guo)(guo)濾海量(liang)惡(e)(e)(e)(e)意(yi)流(liu)(liu)(liu)量(liang)(如(ru)(ru)(ru)(ru)(ru) SYN Flood、HTTP Flood),保障(zhang)企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye) Web 服(fu)務(wu)可用(yong)(yong)(yong)(yong)(yong)(yong)性(xing)。
三、核(he)(he)心(xin)(xin)(xin)優(you)(you)(you)勢(shi)與(yu)(yu)(yu)(yu)適(shi)用(yong)(yong)(yong)(yong)(yong)(yong)場景(jing)
1. 優(you)(you)(you)勢(shi)對(dui)比(vs 傳(chuan)統(tong)(tong)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan))
維度(du) 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)算(suan)(suan) Web 安(an)(an)(an)(an)..關(guan)(guan) 傳(chuan)統(tong)(tong)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)
部(bu)(bu)(bu)署(shu)成(cheng)(cheng)本(ben)(ben) 零硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)投(tou)入(ru)(ru)(ru),按需(xu)(xu)(xu)(xu)(xu)(xu)付費(OPEX 模(mo)式(shi)) 高(gao)(gao)初期投(tou)資(CAPEX),需(xu)(xu)(xu)(xu)(xu)(xu)定(ding)期升級
擴(kuo)展性(xing) 彈性(xing)擴(kuo)展,支(zhi)持(chi)(chi)千萬(wan)級并(bing)發(fa) 受限(xian)(xian)于硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)性(xing)能(neng)(neng)(neng)(neng)(neng),擴(kuo)容復(fu)雜
威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)響(xiang)(xiang)應(ying)(ying)速(su)度(du) 分(fen)(fen)(fen)(fen)鐘級..規(gui)(gui)(gui)則(ze)(ze)更(geng)新(xin)(xin),實(shi)時(shi)(shi)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)情(qing)(qing)報(bao)(bao)共(gong)享(xiang) 依(yi)(yi)賴(lai)手(shou)(shou)動(dong)(dong)(dong)(dong)(dong)更(geng)新(xin)(xin),區域(yu)化(hua)(hua)響(xiang)(xiang)應(ying)(ying)延(yan)(yan)遲(chi)
分(fen)(fen)(fen)(fen)布(bu)(bu)式(shi)部(bu)(bu)(bu)署(shu) 天然支(zhi)持(chi)(chi)多(duo)(duo)(duo)分(fen)(fen)(fen)(fen)支(zhi)機構(gou)(gou)、遠(yuan)程(cheng)辦(ban)公(gong)(gong)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru) 需(xu)(xu)(xu)(xu)(xu)(xu)在每(mei)(mei)個(ge)(ge)節(jie)點(dian)部(bu)(bu)(bu)署(shu)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)設(she)(she)(she)備(bei)(bei)(bei)
管(guan)理(li)(li)(li)(li)復(fu)雜度(du) 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)統(tong)(tong)一(yi)管(guan)理(li)(li)(li)(li),策(ce)略實(shi)時(shi)(shi)生效 多(duo)(duo)(duo)設(she)(she)(she)備(bei)(bei)(bei)獨立配置,策(ce)略同(tong)步困難
2. 典(dian)型應(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong)場景(jing)
分(fen)(fen)(fen)(fen)布(bu)(bu)式(shi)企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru):跨(kua)國公(gong)(gong)司(si)分(fen)(fen)(fen)(fen)支(zhi)機構(gou)(gou)或(huo)遠(yuan)程(cheng)員工(gong)通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)互(hu)(hu)聯(lian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang),無(wu)(wu)需(xu)(xu)(xu)(xu)(xu)(xu)在每(mei)(mei)個(ge)(ge)辦(ban)公(gong)(gong)室(shi)部(bu)(bu)(bu)署(shu)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)設(she)(she)(she)備(bei)(bei)(bei),統(tong)(tong)一(yi)策(ce)略下發(fa)(如(ru)(ru)(ru)(ru)(ru)禁止(zhi)(zhi)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen) P2P 下載(zai)(zai)站點(dian))。
移(yi)動(dong)(dong)(dong)(dong)(dong)辦(ban)公(gong)(gong)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):員工(gong)通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)手(shou)(shou)機、平板等(deng)移(yi)動(dong)(dong)(dong)(dong)(dong)設(she)(she)(she)備(bei)(bei)(bei)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)提(ti)(ti)供(gong)(gong)(gong)跨(kua)平臺的(de)(de)(de)(de)一(yi)致安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)防(fang)護(hu)(hu)(如(ru)(ru)(ru)(ru)(ru)阻(zu)(zu)止(zhi)(zhi)移(yi)動(dong)(dong)(dong)(dong)(dong)設(she)(she)(she)備(bei)(bei)(bei)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)惡(e)(e)(e)(e)意(yi) APK 下載(zai)(zai)頁(ye)(ye)面(mian))。
多(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環境(jing)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)使用(yong)(yong)(yong)(yong)(yong)(yong) AWS、Azure 等(deng)多(duo)(duo)(duo)個(ge)(ge)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)平臺時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)作為(wei)統(tong)(tong)一(yi)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)入(ru)(ru)(ru)口(kou)(kou),避免不(bu)(bu)同(tong)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環境(jing)下的(de)(de)(de)(de)策(ce)略孤(gu)島。
中(zhong)(zhong)小企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)輕量(liang)化(hua)(hua)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan):無(wu)(wu)需(xu)(xu)(xu)(xu)(xu)(xu)專業(ye)(ye)(ye)(ye)(ye)(ye)(ye) IT 團隊維護(hu)(hu),通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)訂閱(yue)制(zhi)獲得企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)級安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)力(li)(如(ru)(ru)(ru)(ru)(ru) URL 過(guo)(guo)(guo)(guo)(guo)濾、反(fan)惡(e)(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)),成(cheng)(cheng)本(ben)(ben)僅(jin)為(wei)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)方案的(de)(de)(de)(de) 1/3~1/2。
四、挑戰與(yu)(yu)(yu)(yu)風(feng)(feng)險(xian)
1. 數(shu)(shu)(shu)據(ju)(ju)隱私(si)與(yu)(yu)(yu)(yu)合(he)規(gui)(gui)(gui)風(feng)(feng)險(xian)
用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)流(liu)(liu)(liu)量(liang)需(xu)(xu)(xu)(xu)(xu)(xu)經(jing)第三方云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)節(jie)點(dian)處(chu)(chu)理(li)(li)(li)(li),可能(neng)(neng)(neng)(neng)(neng)涉及(ji)數(shu)(shu)(shu)據(ju)(ju)跨(kua)境(jing)傳(chuan)輸(shu)合(he)規(gui)(gui)(gui)問(wen)(wen)(wen)題(如(ru)(ru)(ru)(ru)(ru)中(zhong)(zhong)國《數(shu)(shu)(shu)據(ju)(ju)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)法》要求重要數(shu)(shu)(shu)據(ju)(ju)本(ben)(ben)地(di)(di)化(hua)(hua)存(cun)儲(chu))。需(xu)(xu)(xu)(xu)(xu)(xu)選(xuan)擇支(zhi)持(chi)(chi) “區域(yu)化(hua)(hua)數(shu)(shu)(shu)據(ju)(ju)處(chu)(chu)理(li)(li)(li)(li)” 的(de)(de)(de)(de)服(fu)務(wu)商(如(ru)(ru)(ru)(ru)(ru)在本(ben)(ben)地(di)(di)數(shu)(shu)(shu)據(ju)(ju)中(zhong)(zhong)心(xin)(xin)(xin)處(chu)(chu)理(li)(li)(li)(li)境(jing)內流(liu)(liu)(liu)量(liang))。
云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)服(fu)務(wu)商的(de)(de)(de)(de)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)力(li)直接(jie)(jie)(jie)(jie)(jie)影響(xiang)(xiang)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)數(shu)(shu)(shu)據(ju)(ju)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan),需(xu)(xu)(xu)(xu)(xu)(xu)驗(yan)證其 ISO 27001、SOC 2 等(deng)..,以及(ji)數(shu)(shu)(shu)據(ju)(ju)加(jia)(jia)密(mi)措施(shi)(如(ru)(ru)(ru)(ru)(ru)傳(chuan)輸(shu)層 TLS 1.3、存(cun)儲(chu)層 AES-256)。
2. 網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)延(yan)(yan)遲(chi)與(yu)(yu)(yu)(yu)性(xing)能(neng)(neng)(neng)(neng)(neng)影響(xiang)(xiang)
流(liu)(liu)(liu)量(liang)繞行云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)節(jie)點(dian)可能(neng)(neng)(neng)(neng)(neng)增加(jia)(jia)延(yan)(yan)遲(chi)(尤(you)(you)其用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)與(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan) POP 距離較遠(yuan)時(shi)(shi)),需(xu)(xu)(xu)(xu)(xu)(xu)服(fu)務(wu)商通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)邊(bian)緣計(ji)算(suan)(suan)節(jie)點(dian)(Edge POP)或(huo) Anycast 技(ji)術(shu)優(you)(you)(you)化(hua)(hua)路由(理(li)(li)(li)(li)想情(qing)(qing)況下延(yan)(yan)遲(chi)增加(jia)(jia) < 5ms)。
SSL 解密(mi)可能(neng)(neng)(neng)(neng)(neng)消耗(hao)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)算(suan)(suan)力(li),需(xu)(xu)(xu)(xu)(xu)(xu)關(guan)(guan)注服(fu)務(wu)商的(de)(de)(de)(de)并(bing)發(fa)處(chu)(chu)理(li)(li)(li)(li)能(neng)(neng)(neng)(neng)(neng)力(li)(如(ru)(ru)(ru)(ru)(ru)單(dan)節(jie)點(dian)支(zhi)持(chi)(chi) 10Gbps 解密(mi)吞吐量(liang))。
3. 依(yi)(yi)賴(lai)互(hu)(hu)聯(lian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)連接(jie)(jie)(jie)(jie)(jie)
企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)中(zhong)(zhong)斷(duan)時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)無(wu)(wu)法提(ti)(ti)供(gong)(gong)(gong)服(fu)務(wu),需(xu)(xu)(xu)(xu)(xu)(xu)結(jie)合(he)本(ben)(ben)地(di)(di)緩(huan)(huan)存(cun)或(huo)備(bei)(bei)(bei)用(yong)(yong)(yong)(yong)(yong)(yong)鏈(lian)路(如(ru)(ru)(ru)(ru)(ru) SD-WAN)..業(ye)(ye)(ye)(ye)(ye)(ye)(ye)務(wu)連續(xu)(xu)性(xing)。
五、市場現狀與(yu)(yu)(yu)(yu)主流(liu)(liu)(liu)方案
1. 頭部(bu)(bu)(bu)廠商與(yu)(yu)(yu)(yu)產品
Zscaler Internet Access(ZIA):純云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)架(jia)(jia)構(gou)(gou),主打零信(xin)任訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen),支(zhi)持(chi)(chi)實(shi)時(shi)(shi)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)檢(jian)測(ce)(ce)與(yu)(yu)(yu)(yu)數(shu)(shu)(shu)據(ju)(ju)防(fang)泄(xie)(xie)露(lu),.. POP 節(jie)點(dian)超 200 個(ge)(ge)。
Cisco Umbrella:整合(he)域(yu)名解析(xi)層安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(DNS 過(guo)(guo)(guo)(guo)(guo)濾)與(yu)(yu)(yu)(yu) Web 安(an)(an)(an)(an)..關(guan)(guan),通(tong)(tong)過(guo)(guo)(guo)(guo)(guo) Anycast 網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)降低延(yan)(yan)遲(chi),適(shi)合(he)混(hun)合(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環境(jing)。
Forcepoint SWG:提(ti)(ti)供(gong)(gong)(gong)深(shen)度(du)內容檢(jian)測(ce)(ce)(如(ru)(ru)(ru)(ru)(ru)文(wen)檔沙箱分(fen)(fen)(fen)(fen)析(xi)),支(zhi)持(chi)(chi)自定(ding)義(yi)策(ce)略引(yin)(yin)擎(qing),滿足金融(rong)、政府等(deng)高(gao)(gao)合(he)規(gui)(gui)(gui)需(xu)(xu)(xu)(xu)(xu)(xu)求。
Symantec Web Security Service:依(yi)(yi)托(tuo)賽門鐵克..威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)情(qing)(qing)報(bao)(bao),主打惡(e)(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)防(fang)護(hu)(hu)與(yu)(yu)(yu)(yu)合(he)規(gui)(gui)(gui)審計(ji),適(shi)合(he)中(zhong)(zhong)小企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)。
2. 技(ji)術(shu)趨勢(shi)
與(yu)(yu)(yu)(yu) SASE(安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)服(fu)務(wu)邊(bian)緣)融(rong)合(he):Web 安(an)(an)(an)(an)..關(guan)(guan)作為(wei) SASE 架(jia)(jia)構(gou)(gou)的(de)(de)(de)(de)核(he)(he)心(xin)(xin)(xin)組件(jian)(jian)(jian)(jian)(jian)(jian)(jian),與(yu)(yu)(yu)(yu) SD-WAN、零信(xin)任網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)訪(fang)(fang)(fang)(fang)問(wen)(wen)(wen)(ZTNA)等(deng)功(gong)能(neng)(neng)(neng)(neng)(neng)集成(cheng)(cheng),提(ti)(ti)供(gong)(gong)(gong)端(duan)(duan)到端(duan)(duan)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)。
AI 驅(qu)動(dong)(dong)(dong)(dong)(dong)的(de)(de)(de)(de)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)檢(jian)測(ce)(ce):利用(yong)(yong)(yong)(yong)(yong)(yong) NLP 分(fen)(fen)(fen)(fen)析(xi)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)頁(ye)(ye)內容語義(yi)(如(ru)(ru)(ru)(ru)(ru)釣魚郵(you)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)中(zhong)(zhong)的(de)(de)(de)(de)社會工(gong)程(cheng)話術(shu)),結(jie)合(he)行為(wei)分(fen)(fen)(fen)(fen)析(xi)模(mo)型識別(bie)新(xin)(xin)型攻(gong)(gong)擊。
無(wu)(wu)客戶(hu)(hu)(hu)(hu)端(duan)(duan)部(bu)(bu)(bu)署(shu):通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)瀏覽器插件(jian)(jian)(jian)(jian)(jian)(jian)(jian)或(huo) API 集成(cheng)(cheng),簡(jian)化(hua)(hua)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)接(jie)(jie)(jie)(jie)(jie)入(ru)(ru)(ru)流(liu)(liu)(liu)程(cheng),尤(you)(you)其適(shi)用(yong)(yong)(yong)(yong)(yong)(yong)于 BYOD(自帶設(she)(she)(she)備(bei)(bei)(bei))場景(jing)。
總結(jie)
基于云(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)算(suan)(suan)的(de)(de)(de)(de) Web 安(an)(an)(an)(an)..關(guan)(guan)服(fu)務(wu)通(tong)(tong)過(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)(duan)化(hua)(hua)、智能(neng)(neng)(neng)(neng)(neng)化(hua)(hua)和(he)彈性(xing)化(hua)(hua),解決了(le)傳(chuan)統(tong)(tong)硬(ying)件(jian)(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)的(de)(de)(de)(de)部(bu)(bu)(bu)署(shu)成(cheng)(cheng)本(ben)(ben)高(gao)(gao)、擴(kuo)展性(xing)差等(deng)問(wen)(wen)(wen)題,成(cheng)(cheng)為(wei)企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)應(ying)(ying)對(dui)分(fen)(fen)(fen)(fen)布(bu)(bu)式(shi)辦(ban)公(gong)(gong)、多(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)環境(jing)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)的(de)(de)(de)(de)..方案。其核(he)(he)心(xin)(xin)(xin)價值在于將安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)(neng)力(li)轉化(hua)(hua)為(wei)可按需(xu)(xu)(xu)(xu)(xu)(xu)調用(yong)(yong)(yong)(yong)(yong)(yong)的(de)(de)(de)(de) “安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)即服(fu)務(wu)”,同(tong)時(shi)(shi)依(yi)(yi)托(tuo)..威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)情(qing)(qing)報(bao)(bao)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)提(ti)(ti)升防(fang)護(hu)(hu)效率。未來,隨著 SASE 架(jia)(jia)構(gou)(gou)的(de)(de)(de)(de)普及(ji)和(he) AI 技(ji)術(shu)的(de)(de)(de)(de)深(shen)入(ru)(ru)(ru)應(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong),該服(fu)務(wu)將進(jin)一(yi)步融(rong)合(he)網(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)(luo)與(yu)(yu)(yu)(yu)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng)(neng),為(wei)數(shu)(shu)(shu)字(zi)化(hua)(hua)轉型提(ti)(ti)供(gong)(gong)(gong)更(geng)主動(dong)(dong)(dong)(dong)(dong)、更(geng)智能(neng)(neng)(neng)(neng)(neng)的(de)(de)(de)(de)安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)保障(zhang)。企(qi)(qi)(qi)業(ye)(ye)(ye)(ye)(ye)(ye)(ye)在選(xuan)擇時(shi)(shi)需(xu)(xu)(xu)(xu)(xu)(xu)重點(dian)關(guan)(guan)注服(fu)務(wu)商的(de)(de)(de)(de)合(he)規(gui)(gui)(gui)性(xing)、..節(jie)點(dian)覆蓋及(ji)威(wei)(wei)(wei)脅(xie)(xie)(xie)(xie)響(xiang)(xiang)應(ying)(ying)速(su)度(du),平衡安(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)與(yu)(yu)(yu)(yu)性(xing)能(neng)(neng)(neng)(neng)(neng)需(xu)(xu)(xu)(xu)(xu)(xu)求。一、技(ji)(ji)術架(jia)構(gou)(gou)與(yu)(yu)(yu)(yu)核心原理(li)(li)(li)(li)
1. 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)部(bu)(bu)(bu)署模(mo)(mo)式(shi)(shi)(shi)(shi)
SaaS 化(hua)服務(wu)(wu)(wu)(wu)(wu):通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo) Web 界面(mian)或 API 提(ti)(ti)供服務(wu)(wu)(wu)(wu)(wu),用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)無(wu)需(xu)(xu)(xu)(xu)部(bu)(bu)(bu)署本(ben)地(di)硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian),直接(jie)(jie)(jie)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)互聯網(wang)(wang)(wang)(wang)(wang)(wang)接(jie)(jie)(jie)入云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(guan)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) Zscaler、Cisco Umbrella 等(deng))。
分(fen)(fen)(fen)布式(shi)(shi)(shi)(shi)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)覆(fu)蓋:在..多(duo)(duo)(duo)(duo)個(ge)數(shu)(shu)據(ju)(ju)中(zhong)(zhong)心部(bu)(bu)(bu)署 POP(接(jie)(jie)(jie)入點(dian)(dian)(dian)),用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)流(liu)量(liang)(liang)就近接(jie)(jie)(jie)入云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian),經安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)檢(jian)(jian)測(ce)后(hou)轉(zhuan)發(fa)(fa)至目標網(wang)(wang)(wang)(wang)(wang)(wang)站,降低(di)延(yan)遲(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo) Anycast 技(ji)(ji)術優(you)化(hua)路(lu)(lu)由(you))。
與(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)基(ji)礎(chu)設施集(ji)(ji)成(cheng):無(wu)縫對(dui)接(jie)(jie)(jie) AWS、Azure、阿里云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)等(deng)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)平(ping)臺,支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)混合(he)(he)(he)(he)(he)(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun) / 多(duo)(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)(huan)境(jing)下(xia)的(de)(de)(de)(de)統一安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)。
2. 核心技(ji)(ji)術支(zhi)(zhi)撐(cheng)
威(wei)(wei)脅(xie)(xie)(xie)情(qing)報(bao)共享:云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)匯(hui)聚(ju)..用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)的(de)(de)(de)(de)威(wei)(wei)脅(xie)(xie)(xie)數(shu)(shu)據(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)惡(e)(e)(e)意(yi) URL、釣(diao)魚(yu)頁面(mian)、勒索軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)特征),通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)機(ji)器學習實(shi)(shi)時(shi)(shi)更(geng)新檢(jian)(jian)測(ce)模(mo)(mo)型(xing),提(ti)(ti)升(sheng)零(ling)(ling)日攻擊(ji)(ji)識別(bie)能(neng)(neng)(neng)(neng)力(li)(li)。
SSL/TLS 解(jie)密(mi)(mi)與(yu)(yu)(yu)(yu)檢(jian)(jian)測(ce):在云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)對(dui)加(jia)密(mi)(mi)流(liu)量(liang)(liang)(HTTPS)進行解(jie)密(mi)(mi)分(fen)(fen)(fen)析(xi)(xi),檢(jian)(jian)測(ce)隱(yin)藏在加(jia)密(mi)(mi)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)道(dao)中(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)或數(shu)(shu)據(ju)(ju)泄(xie)露行為(wei)(wei)(wei)(需(xu)(xu)(xu)(xu)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)授權證書(shu))。
API 驅(qu)動(dong)(dong)(dong)的(de)(de)(de)(de)策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)引擎:通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)開放 API 接(jie)(jie)(jie)口,企(qi)(qi)業(ye)(ye)可自(zi)定(ding)義(yi)(yi)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)按(an)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)角色(se)、設備(bei)類型(xing)、地(di)理(li)(li)(li)(li)位置限(xian)制訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)),并(bing)與(yu)(yu)(yu)(yu)現(xian)(xian)有(you) IT 系統(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) AD、SIEM)聯動(dong)(dong)(dong)。
二、核心功(gong)能(neng)(neng)(neng)(neng)與(yu)(yu)(yu)(yu)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)力(li)(li)
1. 基(ji)礎(chu)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng)
URL 過(guo)(guo)(guo)(guo)(guo)(guo)濾(lv)與(yu)(yu)(yu)(yu)內(nei)(nei)容(rong)審查:根(gen)據(ju)(ju)預定(ding)義(yi)(yi)規(gui)則(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)行業(ye)(ye)合(he)(he)(he)(he)(he)(he)規(gui)要(yao)(yao)求(qiu)、企(qi)(qi)業(ye)(ye)風險(xian)(xian)(xian)偏(pian)好),攔(lan)截惡(e)(e)(e)意(yi)或違規(gui) URL(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)賭博、釣(diao)魚(yu)網(wang)(wang)(wang)(wang)(wang)(wang)站),支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)細粒度(du)(du)分(fen)(fen)(fen)類(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) “社交(jiao)網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo) - 工(gong)作相關(guan)(guan)(guan)”“文件(jian)(jian)(jian)(jian)(jian)(jian)共享 - 高風險(xian)(xian)(xian)”)。
惡(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)防護(hu):通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)反病毒(du)引擎(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)卡巴斯(si)基(ji)、賽門鐵克)和(he)沙箱分(fen)(fen)(fen)析(xi)(xi),檢(jian)(jian)測(ce)網(wang)(wang)(wang)(wang)(wang)(wang)頁中(zhong)(zhong)的(de)(de)(de)(de)惡(e)(e)(e)意(yi)代(dai)碼(ma)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) JavaScript 注(zhu)(zhu)入、漏洞利用(yong)(yong)(yong)(yong)(yong)(yong)工(gong)具包),阻止(zhi)(zhi)下(xia)載(zai)(zai)惡(e)(e)(e)意(yi)文件(jian)(jian)(jian)(jian)(jian)(jian)。
數(shu)(shu)據(ju)(ju)防泄(xie)露(DLP):掃描上傳(chuan)(chuan)(chuan)(chuan) / 下(xia)載(zai)(zai)的(de)(de)(de)(de)文件(jian)(jian)(jian)(jian)(jian)(jian)內(nei)(nei)容(rong),阻止(zhi)(zhi)敏感數(shu)(shu)據(ju)(ju)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)信(xin)用(yong)(yong)(yong)(yong)(yong)(yong)卡號、醫療記錄(lu))通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo) Web 表(biao)單或文件(jian)(jian)(jian)(jian)(jian)(jian)傳(chuan)(chuan)(chuan)(chuan)輸(shu)泄(xie)露,支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)自(zi)定(ding)義(yi)(yi)數(shu)(shu)據(ju)(ju)指紋(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)正(zheng)則表(biao)達(da)式(shi)(shi)(shi)(shi)匹配)。
2. 進階安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)力(li)(li)
零(ling)(ling)信(xin)任(ren)(ren)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)控(kong)制:基(ji)于(yu) “持(chi)(chi)(chi)(chi)(chi)續驗證,永不信(xin)任(ren)(ren)” 原則,結(jie)合(he)(he)(he)(he)(he)(he)設備(bei)狀態(tai)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)是否安(an)(an)(an)(an)(an)(an)裝(zhuang)殺毒(du)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian))、用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)身(shen)份(多(duo)(duo)(duo)(duo)因素(su)..)和(he)環(huan)(huan)境(jing)風險(xian)(xian)(xian)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)異(yi)常地(di)理(li)(li)(li)(li)位置登錄(lu))動(dong)(dong)(dong)態(tai)授權訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)。
..威(wei)(wei)脅(xie)(xie)(xie)檢(jian)(jian)測(ce):利用(yong)(yong)(yong)(yong)(yong)(yong)行為(wei)(wei)(wei)分(fen)(fen)(fen)析(xi)(xi)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)異(yi)常訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)模(mo)(mo)式(shi)(shi)(shi)(shi))和(he)威(wei)(wei)脅(xie)(xie)(xie)關(guan)(guan)(guan)聯引擎,識別(bie)供應(ying)(ying)(ying)鏈攻擊(ji)(ji)、APT(..持(chi)(chi)(chi)(chi)(chi)續性(xing)(xing)威(wei)(wei)脅(xie)(xie)(xie))等(deng)復(fu)雜攻擊(ji)(ji)鏈。例如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru),檢(jian)(jian)測(ce)同(tong)一 IP 短(duan)時(shi)(shi)間內(nei)(nei)頻(pin)繁訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)多(duo)(duo)(duo)(duo)個(ge)高危(wei)站點(dian)(dian)(dian)。
合(he)(he)(he)(he)(he)(he)規(gui)性(xing)(xing)審計(ji)(ji)(ji):生成(cheng)詳細日志(zhi)報(bao)告(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)記錄(lu)、威(wei)(wei)脅(xie)(xie)(xie)事件(jian)(jian)(jian)(jian)(jian)(jian)詳情(qing)),滿足 GDPR、等(deng)保(bao)(bao) 2.0、HIPAA 等(deng)合(he)(he)(he)(he)(he)(he)規(gui)要(yao)(yao)求(qiu),支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)日志(zhi)一鍵導出至 SIEM 系統。
3. 性(xing)(xing)能(neng)(neng)(neng)(neng)優(you)化(hua)功(gong)能(neng)(neng)(neng)(neng)
緩(huan)存(cun)與(yu)(yu)(yu)(yu)加(jia)速(su)(su):緩(huan)存(cun)靜態(tai)內(nei)(nei)容(rong)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)圖片、CSS/JS 文件(jian)(jian)(jian)(jian)(jian)(jian)),減少重復(fu)下(xia)載(zai)(zai),提(ti)(ti)升(sheng)網(wang)(wang)(wang)(wang)(wang)(wang)頁加(jia)載(zai)(zai)速(su)(su)度(du)(du)(尤其(qi)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)于(yu)跨國(guo)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)場(chang)景)。
流(liu)量(liang)(liang)清洗:通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan) DDoS 防護(hu)模(mo)(mo)塊,過(guo)(guo)(guo)(guo)(guo)(guo)濾(lv)海量(liang)(liang)惡(e)(e)(e)意(yi)流(liu)量(liang)(liang)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) SYN Flood、HTTP Flood),保(bao)(bao)障企(qi)(qi)業(ye)(ye) Web 服務(wu)(wu)(wu)(wu)(wu)可用(yong)(yong)(yong)(yong)(yong)(yong)性(xing)(xing)。
三、核心優(you)勢(shi)與(yu)(yu)(yu)(yu)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)場(chang)景
1. 優(you)勢(shi)對(dui)比(vs 傳(chuan)(chuan)(chuan)(chuan)統硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan))
維(wei)度(du)(du) 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)(ji)(ji)算(suan) Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(guan) 傳(chuan)(chuan)(chuan)(chuan)統硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)
部(bu)(bu)(bu)署成(cheng)本(ben) 零(ling)(ling)硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)投入,按(an)需(xu)(xu)(xu)(xu)付費(OPEX 模(mo)(mo)式(shi)(shi)(shi)(shi)) 高初期投資(CAPEX),需(xu)(xu)(xu)(xu)定(ding)期升(sheng)級(ji)(ji)
擴(kuo)展(zhan)(zhan)性(xing)(xing) 彈(dan)性(xing)(xing)擴(kuo)展(zhan)(zhan),支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)千萬級(ji)(ji)并(bing)發(fa)(fa) 受限(xian)于(yu)硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)性(xing)(xing)能(neng)(neng)(neng)(neng),擴(kuo)容(rong)復(fu)雜
威(wei)(wei)脅(xie)(xie)(xie)響(xiang)應(ying)(ying)(ying)速(su)(su)度(du)(du) 分(fen)(fen)(fen)鐘(zhong)級(ji)(ji)..規(gui)則更(geng)新,實(shi)(shi)時(shi)(shi)威(wei)(wei)脅(xie)(xie)(xie)情(qing)報(bao)共享 依賴手動(dong)(dong)(dong)更(geng)新,區域化(hua)響(xiang)應(ying)(ying)(ying)延(yan)遲
分(fen)(fen)(fen)布式(shi)(shi)(shi)(shi)部(bu)(bu)(bu)署 天然支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)多(duo)(duo)(duo)(duo)分(fen)(fen)(fen)支(zhi)(zhi)機(ji)構(gou)(gou)、遠程(cheng)辦(ban)(ban)公安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)入 需(xu)(xu)(xu)(xu)在每個(ge)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)部(bu)(bu)(bu)署硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)設備(bei)
管(guan)(guan)理(li)(li)(li)(li)復(fu)雜度(du)(du) 云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)統一管(guan)(guan)理(li)(li)(li)(li),策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)實(shi)(shi)時(shi)(shi)生效(xiao) 多(duo)(duo)(duo)(duo)設備(bei)獨立配置,策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)同(tong)步(bu)困(kun)難
2. 典型(xing)應(ying)(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong)場(chang)景
分(fen)(fen)(fen)布式(shi)(shi)(shi)(shi)企(qi)(qi)業(ye)(ye)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)入:跨國(guo)公司分(fen)(fen)(fen)支(zhi)(zhi)機(ji)構(gou)(gou)或遠程(cheng)員(yuan)工(gong)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)互聯網(wang)(wang)(wang)(wang)(wang)(wang),無(wu)需(xu)(xu)(xu)(xu)在每個(ge)辦(ban)(ban)公室部(bu)(bu)(bu)署硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)設備(bei),統一策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)下(xia)發(fa)(fa)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)禁止(zhi)(zhi)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen) P2P 下(xia)載(zai)(zai)站點(dian)(dian)(dian))。
移動(dong)(dong)(dong)辦(ban)(ban)公安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):員(yuan)工(gong)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)手機(ji)、平(ping)板等(deng)移動(dong)(dong)(dong)設備(bei)接(jie)(jie)(jie)入時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)提(ti)(ti)供跨平(ping)臺的(de)(de)(de)(de)一致安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)防護(hu)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)阻止(zhi)(zhi)移動(dong)(dong)(dong)設備(bei)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)惡(e)(e)(e)意(yi) APK 下(xia)載(zai)(zai)頁面(mian))。
多(duo)(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)(huan)境(jing)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):企(qi)(qi)業(ye)(ye)使用(yong)(yong)(yong)(yong)(yong)(yong) AWS、Azure 等(deng)多(duo)(duo)(duo)(duo)個(ge)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)平(ping)臺時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)作為(wei)(wei)(wei)統一安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)入口,避免不同(tong)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)(huan)境(jing)下(xia)的(de)(de)(de)(de)策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)孤島。
中(zhong)(zhong)小企(qi)(qi)業(ye)(ye)輕量(liang)(liang)化(hua)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan):無(wu)需(xu)(xu)(xu)(xu)專業(ye)(ye) IT 團(tuan)隊維(wei)護(hu),通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)訂閱制獲得企(qi)(qi)業(ye)(ye)級(ji)(ji)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)力(li)(li)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) URL 過(guo)(guo)(guo)(guo)(guo)(guo)濾(lv)、反惡(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)),成(cheng)本(ben)僅為(wei)(wei)(wei)硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)方(fang)案的(de)(de)(de)(de) 1/3~1/2。
四、挑戰與(yu)(yu)(yu)(yu)風險(xian)(xian)(xian)
1. 數(shu)(shu)據(ju)(ju)隱(yin)私與(yu)(yu)(yu)(yu)合(he)(he)(he)(he)(he)(he)規(gui)風險(xian)(xian)(xian)
用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)流(liu)量(liang)(liang)需(xu)(xu)(xu)(xu)經第三方(fang)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)處(chu)理(li)(li)(li)(li),可能(neng)(neng)(neng)(neng)涉(she)及(ji)數(shu)(shu)據(ju)(ju)跨境(jing)傳(chuan)(chuan)(chuan)(chuan)輸(shu)合(he)(he)(he)(he)(he)(he)規(gui)問(wen)(wen)(wen)(wen)(wen)(wen)題(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)中(zhong)(zhong)國(guo)《數(shu)(shu)據(ju)(ju)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)法》要(yao)(yao)求(qiu)重要(yao)(yao)數(shu)(shu)據(ju)(ju)本(ben)地(di)化(hua)存(cun)儲(chu))。需(xu)(xu)(xu)(xu)選擇(ze)支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi) “區域化(hua)數(shu)(shu)據(ju)(ju)處(chu)理(li)(li)(li)(li)” 的(de)(de)(de)(de)服務(wu)(wu)(wu)(wu)(wu)商(shang)(shang)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)在本(ben)地(di)數(shu)(shu)據(ju)(ju)中(zhong)(zhong)心處(chu)理(li)(li)(li)(li)境(jing)內(nei)(nei)流(liu)量(liang)(liang))。
云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)服務(wu)(wu)(wu)(wu)(wu)商(shang)(shang)的(de)(de)(de)(de)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)力(li)(li)直接(jie)(jie)(jie)影響(xiang)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)數(shu)(shu)據(ju)(ju)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan),需(xu)(xu)(xu)(xu)驗證其(qi) ISO 27001、SOC 2 等(deng)..,以及(ji)數(shu)(shu)據(ju)(ju)加(jia)密(mi)(mi)措施(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)傳(chuan)(chuan)(chuan)(chuan)輸(shu)層 TLS 1.3、存(cun)儲(chu)層 AES-256)。
2. 網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)延(yan)遲與(yu)(yu)(yu)(yu)性(xing)(xing)能(neng)(neng)(neng)(neng)影響(xiang)
流(liu)量(liang)(liang)繞(rao)行云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)可能(neng)(neng)(neng)(neng)增加(jia)延(yan)遲(尤其(qi)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)與(yu)(yu)(yu)(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan) POP 距離較遠時(shi)(shi)),需(xu)(xu)(xu)(xu)服務(wu)(wu)(wu)(wu)(wu)商(shang)(shang)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)邊緣計(ji)(ji)(ji)算(suan)節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)(Edge POP)或 Anycast 技(ji)(ji)術優(you)化(hua)路(lu)(lu)由(you)(理(li)(li)(li)(li)想情(qing)況下(xia)延(yan)遲增加(jia) < 5ms)。
SSL 解(jie)密(mi)(mi)可能(neng)(neng)(neng)(neng)消耗云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)算(suan)力(li)(li),需(xu)(xu)(xu)(xu)關(guan)(guan)(guan)注(zhu)(zhu)服務(wu)(wu)(wu)(wu)(wu)商(shang)(shang)的(de)(de)(de)(de)并(bing)發(fa)(fa)處(chu)理(li)(li)(li)(li)能(neng)(neng)(neng)(neng)力(li)(li)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)單節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi) 10Gbps 解(jie)密(mi)(mi)吞吐(tu)量(liang)(liang))。
3. 依賴互聯網(wang)(wang)(wang)(wang)(wang)(wang)連接(jie)(jie)(jie)
企(qi)(qi)業(ye)(ye)網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)中(zhong)(zhong)斷時(shi)(shi),云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)無(wu)法提(ti)(ti)供服務(wu)(wu)(wu)(wu)(wu),需(xu)(xu)(xu)(xu)結(jie)合(he)(he)(he)(he)(he)(he)本(ben)地(di)緩(huan)存(cun)或備(bei)用(yong)(yong)(yong)(yong)(yong)(yong)鏈路(lu)(lu)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru) SD-WAN)..業(ye)(ye)務(wu)(wu)(wu)(wu)(wu)連續性(xing)(xing)。
五(wu)、市場(chang)現(xian)(xian)狀與(yu)(yu)(yu)(yu)主(zhu)流(liu)方(fang)案
1. 頭部(bu)(bu)(bu)廠商(shang)(shang)與(yu)(yu)(yu)(yu)產(chan)品
Zscaler Internet Access(ZIA):純云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)架(jia)構(gou)(gou),主(zhu)打(da)零(ling)(ling)信(xin)任(ren)(ren)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen),支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)實(shi)(shi)時(shi)(shi)威(wei)(wei)脅(xie)(xie)(xie)檢(jian)(jian)測(ce)與(yu)(yu)(yu)(yu)數(shu)(shu)據(ju)(ju)防泄(xie)露,.. POP 節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)超(chao) 200 個(ge)。
Cisco Umbrella:整合(he)(he)(he)(he)(he)(he)域名解(jie)析(xi)(xi)層安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)(DNS 過(guo)(guo)(guo)(guo)(guo)(guo)濾(lv))與(yu)(yu)(yu)(yu) Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(guan),通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo) Anycast 網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)降低(di)延(yan)遲,適(shi)(shi)合(he)(he)(he)(he)(he)(he)混合(he)(he)(he)(he)(he)(he)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)(huan)境(jing)。
Forcepoint SWG:提(ti)(ti)供深度(du)(du)內(nei)(nei)容(rong)檢(jian)(jian)測(ce)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)文檔沙箱分(fen)(fen)(fen)析(xi)(xi)),支(zhi)(zhi)持(chi)(chi)(chi)(chi)(chi)自(zi)定(ding)義(yi)(yi)策(ce)(ce)(ce)略(lve)(lve)(lve)(lve)引擎,滿足金融(rong)、政府(fu)等(deng)高合(he)(he)(he)(he)(he)(he)規(gui)需(xu)(xu)(xu)(xu)求(qiu)。
Symantec Web Security Service:依托(tuo)賽門鐵克..威(wei)(wei)脅(xie)(xie)(xie)情(qing)報(bao),主(zhu)打(da)惡(e)(e)(e)意(yi)軟(ruan)件(jian)(jian)(jian)(jian)(jian)(jian)防護(hu)與(yu)(yu)(yu)(yu)合(he)(he)(he)(he)(he)(he)規(gui)審計(ji)(ji)(ji),適(shi)(shi)合(he)(he)(he)(he)(he)(he)中(zhong)(zhong)小企(qi)(qi)業(ye)(ye)。
2. 技(ji)(ji)術趨(qu)勢(shi)
與(yu)(yu)(yu)(yu) SASE(安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)服務(wu)(wu)(wu)(wu)(wu)邊緣)融(rong)合(he)(he)(he)(he)(he)(he):Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(guan)作為(wei)(wei)(wei) SASE 架(jia)構(gou)(gou)的(de)(de)(de)(de)核心組件(jian)(jian)(jian)(jian)(jian)(jian),與(yu)(yu)(yu)(yu) SD-WAN、零(ling)(ling)信(xin)任(ren)(ren)網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)訪(fang)(fang)問(wen)(wen)(wen)(wen)(wen)(wen)(ZTNA)等(deng)功(gong)能(neng)(neng)(neng)(neng)集(ji)(ji)成(cheng),提(ti)(ti)供端(duan)到端(duan)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)接(jie)(jie)(jie)入。
AI 驅(qu)動(dong)(dong)(dong)的(de)(de)(de)(de)威(wei)(wei)脅(xie)(xie)(xie)檢(jian)(jian)測(ce):利用(yong)(yong)(yong)(yong)(yong)(yong) NLP 分(fen)(fen)(fen)析(xi)(xi)網(wang)(wang)(wang)(wang)(wang)(wang)頁內(nei)(nei)容(rong)語(yu)義(yi)(yi)(如(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)(ru)釣(diao)魚(yu)郵件(jian)(jian)(jian)(jian)(jian)(jian)中(zhong)(zhong)的(de)(de)(de)(de)社會工(gong)程(cheng)話術),結(jie)合(he)(he)(he)(he)(he)(he)行為(wei)(wei)(wei)分(fen)(fen)(fen)析(xi)(xi)模(mo)(mo)型(xing)識別(bie)新型(xing)攻擊(ji)(ji)。
無(wu)客(ke)戶(hu)(hu)(hu)(hu)端(duan)部(bu)(bu)(bu)署:通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)瀏覽器插件(jian)(jian)(jian)(jian)(jian)(jian)或 API 集(ji)(ji)成(cheng),簡化(hua)用(yong)(yong)(yong)(yong)(yong)(yong)戶(hu)(hu)(hu)(hu)接(jie)(jie)(jie)入流(liu)程(cheng),尤其(qi)適(shi)(shi)用(yong)(yong)(yong)(yong)(yong)(yong)于(yu) BYOD(自(zi)帶設備(bei))場(chang)景。
總結(jie)
基(ji)于(yu)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)計(ji)(ji)(ji)算(suan)的(de)(de)(de)(de) Web 安(an)(an)(an)(an)(an)(an)..關(guan)(guan)(guan)服務(wu)(wu)(wu)(wu)(wu)通(tong)(tong)(tong)(tong)(tong)(tong)(tong)過(guo)(guo)(guo)(guo)(guo)(guo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)端(duan)化(hua)、智能(neng)(neng)(neng)(neng)化(hua)和(he)彈(dan)性(xing)(xing)化(hua),解(jie)決(jue)了傳(chuan)(chuan)(chuan)(chuan)統硬(ying)(ying)件(jian)(jian)(jian)(jian)(jian)(jian)網(wang)(wang)(wang)(wang)(wang)(wang)關(guan)(guan)(guan)的(de)(de)(de)(de)部(bu)(bu)(bu)署成(cheng)本(ben)高、擴(kuo)展(zhan)(zhan)性(xing)(xing)差等(deng)問(wen)(wen)(wen)(wen)(wen)(wen)題,成(cheng)為(wei)(wei)(wei)企(qi)(qi)業(ye)(ye)應(ying)(ying)(ying)對(dui)分(fen)(fen)(fen)布式(shi)(shi)(shi)(shi)辦(ban)(ban)公、多(duo)(duo)(duo)(duo)云(yun)(yun)(yun)(yun)(yun)(yun)(yun)(yun)環(huan)(huan)境(jing)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)的(de)(de)(de)(de)..方(fang)案。其(qi)核心價值在于(yu)將安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)能(neng)(neng)(neng)(neng)力(li)(li)轉(zhuan)化(hua)為(wei)(wei)(wei)可按(an)需(xu)(xu)(xu)(xu)調用(yong)(yong)(yong)(yong)(yong)(yong)的(de)(de)(de)(de) “安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)即服務(wu)(wu)(wu)(wu)(wu)”,同(tong)時(shi)(shi)依托(tuo)..威(wei)(wei)脅(xie)(xie)(xie)情(qing)報(bao)網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)提(ti)(ti)升(sheng)防護(hu)效(xiao)率。未來,隨著(zhu) SASE 架(jia)構(gou)(gou)的(de)(de)(de)(de)普(pu)及(ji)和(he) AI 技(ji)(ji)術的(de)(de)(de)(de)深入應(ying)(ying)(ying)用(yong)(yong)(yong)(yong)(yong)(yong),該服務(wu)(wu)(wu)(wu)(wu)將進一步(bu)融(rong)合(he)(he)(he)(he)(he)(he)網(wang)(wang)(wang)(wang)(wang)(wang)絡(luo)與(yu)(yu)(yu)(yu)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)功(gong)能(neng)(neng)(neng)(neng),為(wei)(wei)(wei)數(shu)(shu)字(zi)化(hua)轉(zhuan)型(xing)提(ti)(ti)供更(geng)主(zhu)動(dong)(dong)(dong)、更(geng)智能(neng)(neng)(neng)(neng)的(de)(de)(de)(de)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)保(bao)(bao)障。企(qi)(qi)業(ye)(ye)在選擇(ze)時(shi)(shi)需(xu)(xu)(xu)(xu)重點(dian)(dian)(dian)關(guan)(guan)(guan)注(zhu)(zhu)服務(wu)(wu)(wu)(wu)(wu)商(shang)(shang)的(de)(de)(de)(de)合(he)(he)(he)(he)(he)(he)規(gui)性(xing)(xing)、..節(jie)(jie)(jie)(jie)點(dian)(dian)(dian)覆(fu)蓋及(ji)威(wei)(wei)脅(xie)(xie)(xie)響(xiang)應(ying)(ying)(ying)速(su)(su)度(du)(du),平(ping)衡(heng)安(an)(an)(an)(an)(an)(an)全(quan)(quan)(quan)(quan)(quan)(quan)(quan)與(yu)(yu)(yu)(yu)性(xing)(xing)能(neng)(neng)(neng)(neng)需(xu)(xu)(xu)(xu)求(qiu)。
(聲明:本文(wen)來(lai)源于(yu)網絡,僅(jin)供(gong)參考閱讀,涉(she)及侵(qin)權(quan)請聯(lian)系我們刪除、不(bu)代表任(ren)何立場以及觀(guan)點。)