字号 ·· | 护眼
theregister

前X-Force黑客追逐进攻性网络淘金热Former X-Force hackers chase the offensive cyber gold rush

点「原文对照」整页切到原文,或双击某段只看那段的原文。

IBM X-Force Red团队的两名前负责人创立了网络安全攻击公司RemoteThreat,并获得700万美元种子前融资。公司首席执行官克里斯·汤普森和首席技术官肖恩·琼斯表示,其平台利用人工智能规划、执行并调整网络攻击行动,能力超越了其他自动化安全工具所提供的持续渗透测试和漏洞检测服务。汤普森和琼斯曾负责X-Force Red团队,该团队受雇对核电站、关键基础设施和大型银行进行安全测试。

Two former leaders of IBM's X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. CEO Chris Thompson and CTO Shawn Jones say the company's platform uses AI to plan, execute, and adapt offensive cyber operations, extending beyond the continuous penetration testing and vulnerability detection offered by other automated security tools. Thompson and Jones previously ran X-Force Red, where their team was hired to test nuclear power plants, critical infrastructure, and major banks.

2024年5月,汤普森告诉《The Hacker News》,X-Force曾利用人工智能在8小时内攻入一家半导体制造商的网络。此后,两人创办了仅限受邀者参加的Offensive AI Con研讨会,第二届会议计划于10月初举行。汤普森在采访中告诉《The Hacker News》:“我们正在观察当前的前沿模型,它们的输出噪声很多,但能力也非常强。我们开始思考:如果它们能够做到我们这些世界顶尖红队成员所能做到的事,会发生什么?”

In May 2024, Thompson told The how X-Force used AI to break into a semiconductor manufacturer's network in eight hours. The pair subsequently created Offensive AI Con, an invitation-only research event whose second edition is scheduled for early October. "We're looking at how noisy but very capable frontier models are right now, and we started to think: What happens when they can do what we can do as one of the best groups of red-teamers in the world?" Thompson told The in an interview.

他表示,令人担忧的是,人工智能可能生成质量接近国家支持型攻击者所用恶意软件的定制恶意软件,并以前所未有的速度和规模部署。RemoteThreat的15名员工包括来自X-Force Adversary Services、Mandiant、SpecterOps、Dreadnode、Bugcrowd、微软、防务承包商和政府机构的资深攻击操作人员、安全研究人员、工程师和恶意软件开发人员。

He said the concern was that AI could produce custom malware approaching the quality used by state-sponsored attackers, then deploy it at unprecedented speed and scale. RemoteThreat's 15 employees include senior operators, security researchers, engineers, and malware developers from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies.

RemoteThreat表示,其平台让防御方和政府操作人员能够获得其对手可能借助人工智能获得的速度和规模。这家初创公司称,其客户已包括一家大型银行、一家证券交易所运营商、一家美国大型医疗保健公司以及一家领先的人工智能实验室。汤普森说:“我们的目标是帮助这些《财富》500强组织更好地模拟 nation-state 级别的攻击。”

RemoteThreat says its platform gives defenders and government operators access to the same speed and scale that AI may offer their adversaries. According to the startup, its customers already include a major bank, a securities exchange operator, a large US healthcare company, and a leading AI lab. "We're focused on preparing these Fortune 500 organizations to better simulate this nation-state level of attack," Thompson said.

另一方面,该平台也为政府提供了必要的工具,以便其能够尽快识别并打击对手。RemoteThreat将其平台描述为一个由八个相互连接的系统组成的整体,这些系统涵盖了任务规划、指挥与控制、攻击手段的部署、初始入侵方式、高级攻击能力、数据混淆技术、数据分析以及人工智能辅助的操作等功能。鉴于该平台存在被滥用的风险,RemoteThreat明确表示只有经过严格审查的企业、国防承包商以及美国政府客户才能使用该平台。

"And then on the flip side, provide the government with the tooling to target their adversaries as quickly as possible." RemoteThreat describes its platform as eight connected systems covering mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI-assisted operations. Given the obvious potential for misuse, RemoteThreat says access is restricted to vetted enterprises, defense contractors, and US government customers.

在某些特定任务中,该平台会使用专门为这些任务开发的小型人工智能模型;客户还可以选择使用 OpenAI 或 Anthropic 提供的模型,或者选择其他开源的人工智能模型。Thompson 表示,这些人工智能模型可以访问 RemoteThreat 自己开发的“1000 种工具”。该平台既可以由人类操作,也可以由人工智能代理来执行各种任务。

The platform uses small, purpose-built models for some tasks. Customers can also connect models from OpenAI or Anthropic, or use an open-weight alternative, giving the chosen LLM access to what Thompson described as "1,000 tools that we've built from scratch." The platform can be operated by either humans or AI agents. Customers can "drive a lot of this testing from your Codex terminal instead of having toto our website, for example," Thompson said.

例如,客户可以通过自己的终端(如 Codex)来进行大部分测试工作,而无需访问 RemoteThreat 的官方网站。RemoteThreat 表示,其技术既可以作为独立平台使用,也可以作为合作伙伴产品的组成部分被集成到其他产品中。该公司已与 Talon Defense 合作——Talon Defense 为国家安全、国防及情报机构提供人工智能和网络技术支持;同时,RemoteThreat 也与 Nakasone Group 建立了合作关系。

RemoteThreat says its capabilities can run within the complete platform or be integrated as components of partners' products. It has teamed up with Talon Defense, which supplies AI and cyber technology to national security, defense, and intelligence customers. RemoteThreat has also partnered with the Nakasone Group, the national security advisory firm founded by retired US Army Gen. Paul Nakasone, former director of the National Security Agency and commander of US Cyber Command.

Nakasone Group 是由退役的美国陆军将军 Paul Nakasone 创立的,他曾担任美国国家安全局局长和美国网络司令部的指挥官,目前也是这家初创公司的战略顾问。此次产品的发布正值华盛顿政府寻求私营部门在网络攻击行动中发挥更大作用之际:美国于 3 月发布的《网络战略》文件呼吁加强与私营部门的合作,共同执行防御性和进攻性网络任务;8 月份发布的总统备忘录进一步要求成立相关机制,允许经过审查的美国公司在美国政府的指导和监督下对外国网络犯罪组织发起网络攻击。

Nakasone is also a strategic adviser to the startup. The launch comes as Washington seeks a larger private-sector role in offensive cyber operations. The US Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions. An August presidential memorandum goes further, ordering the creation of a program through which vetted US companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight.

RemoteThreat还表示,该公司已加入美国特种作战司令部的“特种作战部队快速采购联盟”(SOF RACER)。该联盟旨在为特种作战部队提供所需的技术与装备。汤普森预计,政府将会更加广泛地使用商业开发的进攻性网络产品,既用于支持现有的任务团队,也用于打击网络犯罪组织。他表示:“这个领域目前正处于‘淘金热’阶段——因为这是首次在所有主要项目中,政府都被迫与商业部门合作。”RemoteThreat正致力于提供那些能够用于入侵他人网络的技术与工具。

RemoteThreat also says it has joined US Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements, or SOF RACER, which provides a route for supplying capabilities to special operations forces. Thompson expects the government to make greater use of commercially developed offensive cyber products, both to support existing mission teams and to pursue cybercriminal groups. "It's a bit of a gold rush in this space because this is the first time, across every major program, the government is being pushed to work with the commercial sector," he said. RemoteThreat is positioning itself to supply the picks and shovels – albeit ones capable of breaking into somebody else's network. ®