作者质疑渗透测试与态势评估的局限性
作者表示,包括渗透测试和态势评估在内的传统方法往往存在局限,因为它们主要识别理论风险或无法扩展。他们指出,恶意智能体几乎可以瞬间将风险转化为攻击,而渗透测试“在交付的那一刻就已过时”。
支持这项说法
压制AI武器化:我们对A Security的投资
如今这种局面,已不能靠改造旧办法来应对。传统方法,比如渗透测试和安全态势评估,往往存在局限:它们要么主要识别理论上的风险,要么难以扩大规模。但风险只停留在理论层面的日子已经过去。如今,恶意智能体几乎可以瞬间把风险热点变成现实中的攻击。渗透测试交付之时,就已经过时。
原始摘录
You can’t retrofit this moment. Legacy approaches – pentests and posture assessments for example – are often limited because they either primarily identify areas of theoretical risk, or because they cannot scale. But the days of theoretical risk are over. Today malicious agents can turn a risk hot-spot into a real-world attack almost instantly. That pentest is out of date the moment it ships.
上下文
如今的防御者需要一个速度能超过武器化 AI 的平台,在恶意智能体真正利用漏洞利用路径之前,发现、演示、验证并修复这些路径。
原始上下文
Defenders today need a platform that can outpace weaponized AI, finding, demonstrating, validating, and remediating exploit paths before a malicious agent can actually exploit them.