字号·· | 护眼
axios新闻网

独家:Anthropic保护关键基础设施的计划Exclusive: Anthropic's plan to protect critical infrastructure

点「原文对照」整页切到原文,或双击某段只看那段的原文。

插图:Aïda Amer/Axios。图片来源:Getty ImagesIllustration: Aïda Amer/Axios. Stock: Getty Images

Anthropic 正在推出一项新的网络安全计划,旨在将其最强大的 AI 模型和工程师提供给保护电网、水务公司及其他关键基础设施的企业,该公司首次向 Axios 透露此事。

Anthropic is launching a new cybersecurity initiative designed to bring its most powerful AI models and engineers to companies protecting power grids, water utilities and other critical infrastructure, the company first shared with Axios. Why it matters:

为何重要:关键基础设施运营商正面临保护老化、复杂系统的困难,而 AI 可能使网络攻击变得更快、更便宜。

Critical infrastructure operators are struggling to secure aging, complex systems as AI threatens to make cyberattacks faster and cheaper to execute.

新闻驱动因素:在其新的关键基础设施防御计划下,Anthropic 将向已负责保障关键基础设施系统的公司提供前沿 AI 模型、现场工程师和威胁研究。

Driving the news: Under its new Critical Infrastructure Defense Program, Anthropic will provide its frontier AI models, on-site engineers and threat research to companies already responsible for securing critical infrastructure systems.

  • 参与公司将利用这些资源识别并修复其客户系统中的漏洞。

• Participating companies will use these resources to identify and fix vulnerabilities in their customers' systems.

  • 该计划的创始合作伙伴包括 Accenture、Booz Allen Hamilton、CrowdStrike、Deloitte、Dragos、Hitachi、Insane Cyber、Nozomi Networks、Palo Alto Networks、PwC 和 Rockwell Automation。

• The program's founding partners include Accenture, Booz Allen Hamilton, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

  • Anthropic 表示,已有多家合作伙伴使用 Claude 修复漏洞,并帮助客户做到同样的工作。

• Anthropic said several partners are already using Claude to fix vulnerabilities and help customers do the same. Zoom in:

深入了解: Anthropic 还推出了一项免费 AI 驱动的开源软件项目漏洞扫描服务,名为 OSS Scanner。

Anthropic is also launching a free AI-powered vulnerability scanning service for open-source software projects, called OSS Scanner.

  • 参与项目将定期收到 Claude 的扫描结果,以及自动生成的报告,详细说明漏洞、可能的利用方式和建议的修复方案。

• Participating projects will receive periodic scans from Claude, along with automated reports detailing vulnerabilities, how they could be exploited and suggested fixes.

  • 这些报告在发送给软件维护者之前不会经过人工审查,这意味着部分发现可能不准确。

• The reports won't undergo human review before being sent to software maintainers, meaning some findings could be inaccurate.

全局视角: Anthropic、OpenAI 以及其他 AI 开发商正寻找将其最强大模型交到网络防御者手中的方法,因为黑客也在获取类似的能力。Anthropic 的新举措建立在 Project Glasswing 的经验基础上,后者向经过审查的组织提供其最强 AI 模型,以识别安全漏洞。

The big picture: Anthropic, OpenAI and other AI developers are looking for ways to put their most powerful models in the hands of cyber defenders as hackers gain access to similar capabilities • Anthropic's new initiative builds on lessons from Project Glasswing, which gave vetted organizations access to its most capable AI models to identify security vulnerabilities.

  • 该公司表示,该项目展示了人工智能能够以多快速度发现漏洞,但也说明了验证和修复这些漏洞依然有多么困难。

• The company said the project demonstrated how quickly AI can uncover vulnerabilities, but also how difficult it remains to verify and fix them. Yes, but:

然而:目前尚不清楚参与企业如何在不干扰公用事业运营的情况下安全地测试和部署修复方案,这是保护关键基础设施面临的最大挑战之一。

It's unclear how participating companies will safely test and deploy fixes without disrupting utilities' operations, one of the biggest challenges in securing critical infrastructure.

  • Anthropic 也未说明合作伙伴是否将获得免费的模型访问权限,或是由谁来承担使用其人工智能工具所相关的计算成本。

• Anthropic also didn't specify whether partners will receive free model access or who will cover the computing costs associated with using its AI tools.