Red Hat 正在引領代理式人工智慧 (AI) 的使用,將漏洞管理從重視數量轉向精準導向。藉由將 Red Hat OpenShift 經過安全性強化的基礎,與來自 NVIDIA 的進階 AI 框架結合,我們正提供具備行動力的安全性情報,為企業帶來真正的商業價值。
問題所在:單一軟體套件可能會觸發數百個警示,因為其中一個導入的功能或程式庫在理論上存在漏洞。傳統掃描程式僅止於套件層級,針對您的應用程式中實際上永遠無法觸及的漏洞,產生大量的誤報。團隊被迫浪費無數小時來歸類在實務中並不存在的風險。
這就是 Red Hat Trusted Profile Analyzer(包含漏洞利用情報功能)從根本上改變此一動態之處。
其分析範圍不僅止於套件。漏洞利用情報的代理式 AI 會對您實際的應用程式程式碼路徑執行深入的功能層級分析。它會追蹤執行流,以明確判定: 在您的應用程式情境中,特定的漏洞功能是否可觸及且可執行?
如果該功能無法觸及、無法執行或已透過其他方式緩解,漏洞利用情報就會自動宣告該漏洞在您的環境中無法被利用。這種從套件級雜訊到功能級可利用性分析的轉變,是真正的突破。結果既簡單又具變革性:您的安全性團隊不再需要追逐數百個理論上的漏洞,而可以將精力專注於那些真正可被利用並構成實際業務風險的漏洞上。
提供 AI 與傳統應用程式的首選平台
隨著各組織爭相採用生成式 AI,他們在如何在資料不離開其環境的情況下安全地建立與部署這些模型方面,面臨著嚴峻的挑戰。 Red Hat OpenShift AI 可作為傳統工作負載與注入 AI 之應用程式的開發平台,讓團隊能更安全地部署符合數位主權要求的 AI。
透過我們與 NVIDIA 的合作,Red Hat 正在實現企業級 AI。此項合作已從硬體操作員迅速演變為共同開發的解決方案,包括將 NVIDIA NIM 整合至 OpenShift AI、DGX 硬體驗證,以及像是
漏洞利用情報:透過代理式精準度實現業務價值
這種代理式 AI 價值最明顯的範例就是漏洞利用情報,這是一項建立在 NVIDIA Morpheus Agent 與 NVIDIA NeMo Agent Toolkit 之上的功能。
漏洞利用情報代理式工作流程內部運作
漏洞利用情報實作了精密的「規劃與執行」代理式工作流程,以提供可經由人工驗證的證明。以下是 AI 代表安全性分析師採取行動的方式:
- 輸入與情境導入:漏洞利用情報會接收容器映像的軟體物料清單 (SBOM) 以及目標通用漏洞披露 (CVE)。然後,它會從各種權威來源提取相應的 CVE 情報,並結合使用者的特定詳細資訊(如果有)。接著,它會提取容器的內容,並為檢查程序進行準備。
- 大型語言模型 (LLM) 規劃:規劃代理程式會根據從公共來源(國家弱點資料庫、GitHub、Red Hat 的安全性資料串流等)收集的漏洞情報,產生具備內容感知能力的工作檢查清單。這份檢查清單定義了驗證 CVE 是否可在此特定應用程式中利用的具體步驟。
- 代理程式執行:代理程式會逐一執行檢查清單中的步驟。Red Hat 已開發出程式碼分析工具,可在程式碼庫中尋找函式模式並探索關係,收集有關函式可存取性、執行路徑、環境設定和其他現有控制措施的精確證據。
- 綜合與判斷:分類與推理代理程式會彙總結果並做出判斷。例如,如果程式碼無法存取,它會指派「無法利用」狀態,並產生人類可讀的明確理由(
code_not_reachable或protected_by_compiler,取決於程式碼執行路徑和易受攻擊的函式參數)。
與受信任的軟體工廠整合
若能與開發人員生態系統深度整合,代理式人工智慧 (AI) 就能發揮最大價值。漏洞利用情報是
- Red Hat Trusted Profile Analyzer:Trusted Profile Analyzer 透過 SBOM 管理您的軟體風險概況。當 Trusted Profile Analyzer 偵測到 CVE 時,可以觸發漏洞利用情報。如果漏洞利用情報確定 CVE 為誤報,則會自動產生符合業界標準的 CSAF VEX(通用安全性諮詢架構弱點利用交換)檔案。Trusted Profile Analyzer 會導入此 VEX 檔案,以減少不必要的雜訊。
- Red Hat Trusted Artifact Signer:在漏洞利用情報分析程式碼內容時,Red Hat Trusted Artifact Signer 會以加密方式簽署軟體成品和 AI 模型,有助於提供溯源資訊,並保證漏洞利用情報分析的程式碼在部署前未經篡改。
- 受信任的軟體工廠:比照 Red Hat 內部建置系統的受信任軟體工廠參考實作,可透過 Red Hat Advanced Developer Suite 為企業客戶提供與 Red Hat 自家產品相同的嚴格安全性標準。
Red Hat Advanced Cluster Security for Kubernetes页面当前以 English (英文) 显示(暂无 Chinese, Traditional 选项) :透過 Red Hat Advanced Cluster Security 整合,漏洞利用情報的價值可直接延伸至您的執行階段環境。Red Hat Advanced Cluster Security 可將 CVE 標記為「誤報」,因此不會產生警示(違規)。如此一來可減少「雜訊」,讓安全性團隊專注於那些具備實質風險的 CVE。
透過利用 Red Hat OpenShift、NVIDIA 的 AI 架構,以及全方位的 Red Hat Advanced Developer Suite 產品組合,平台工程師可以排除雜訊。漏洞利用情報證明了代理式 AI 可以是實用且高效的工具,能大幅提升開發速度,並強化企業軟體供應鏈。
了解詳情:
About the authors
James Labocki is senior director of Product Management at Red Hat.
Sudhir Prasad is a Director of Product Management at Red Hat, where he leads the Software Supply Chain Security portfolio. He is responsible for defining product vision, strategy, and execution across multiple enterprise security platforms, helping organizations build, deliver, and operate software securely at scale.
At Red Hat, Sudhir has played a key role in incubating and scaling new software supply chain security products and driving enterprise adoption. His work spans secure software supply chains, artifact signing, security and compliance policy enforcement, secure application pipelines, and compliance automation. In addition, Sudhir drives Red Hat's strategy and execution around AI application and model safety and security, with a focus on enabling secure and compliant AI adoption in regulated and security-sensitive environments. His recent work includes AI-driven initiatives for CVE exploitability analysis, risk assessment, and compliance across structured and unstructured data.
Prior to his current role, Sudhir led product management for Red Hat’s Storage and Data Services portfolios and has held senior product leadership roles at Violin Memory, NetApp, and HP.
Sudhir holds an MBA from Northwestern University’s Kellogg School of Management. He is passionate about building enterprise platforms at the intersection of security, AI, and cloud infrastructure.
More like this
紅帽收購 Chatterbox Labs:常見問題
借助 Red Hat Enterprise Linux (RHEL) 9.7 為後量子未來做好準備
Can Compliance Be A Piece Of Cake? | Compiler
Collaboration In Product Security | Compiler
Keep exploring
- What is agentic AI?
Article - Predictive AI vs. generative AI
Article Top considerations for building a production-ready AI/ML environment E-book 页面当前以 English (英文) 显示(暂无 Chinese, Traditional 选项)- Generative AI, the Ansible way
Video Innovate and transform with a modern application platform页面当前以 English (英文) 显示(暂无 Chinese, Traditional 选项) E-book 页面当前以 English (英文) 显示(暂无 Chinese, Traditional 选项)
Browse by channel
Automation
The latest on IT automation that spans tech, teams, and environments
Artificial intelligence
Explore the platforms and partners building a faster path for AI
Cloud services
Get updates on our portfolio of managed cloud services
Security
Explore how we reduce risks across environments and technologies
Edge computing
Updates on the solutions that simplify infrastructure at the edge
Infrastructure
Stay up to date on the world’s leading enterprise Linux platform
Applications
The latest on our solutions to the toughest application challenges
Original shows
Entertaining stories from the makers and leaders in enterprise tech