paloalto 2024年 云原生安全报告 .docxVIP

  • 0
  • 0
  • 约5.05万字
  • 约 50页
  • 2026-02-10 发布于浙江
  • 举报

EXECUTIVESUMMARY

ARetrospectonthePreviousYear

Webeginourexplorationofthe2024stateofcloud-nativesecuritywithalookbackattheeventsandinfluencesof2023,eachofwhichfactorsintoourcurrentpostures,thechallengesweconfront,andthestrategieswe’vechosentoachieveourdesiredoutcomes.

Whileagiledevelopment,open-sourcesoftware,andcloud-nativetechnologiesgainedmomentumin2023,attackstargetingtheapplicationlayerhavebecomeanestablishedtrend.The

cloud-nativeecosystemgrappledwithasurgeinsupplychainattacks,highlightingtheprevalenceofvulnerabilitiesin

1open-sourcesoftwareandthird-partylibraries.Real-worlddataanalyzedbyourUnit42teamenhancedthispicture,identifyingthecloudasthedominantattacksurface,with80%ofmedium,high,andcriticalexposuresfoundincloud-hostedassets.

1

Forsometime,we’veprioritizedapplicationandinfrastructuresecurity.Butwemustn’tforgetthatthird,

all-importantballintheair.Withtheglobaldataspherereaching120zettabytesin2023,2securingsensitivedataremainsmissioncritical.Thechallengesofmonitoringandcontrollingsensitiveinformation,however,haveescalated.

1CortexXpanseASMThreatReport20232DataCreatedWorldwide2010-2025

2 TheStateofCloud-NativeSecurity

Cloudsecurityisasmuchabusinessgoalasanythingelseweendeavortoachieve.

What’smore,generativeAIemergedin2023asagroundbreakingforcewiththepotentialtohalvedevelopmenttimeandcosts,ultimatelyredefiningtheapplicationeconomy.3Butmuchlikethe

cloudanditsmyriadbenefitsinextricablytiedtochallengeswemustaddress,generativeAIasadevelopmenttoolcomescounterweightedwithconcerns.WehadnosoonerbeguntowonderaboutpotentialissueswhenOWASPreleasedtheTop10LLMSecurityRisksforsecurityteams,alertingustopromptinjection,insecureoutputhandling,

andnewavenuesforsupplychainvulnerabilitiesandsensiti

您可能关注的文档

文档评论(0)

1亿VIP精品文档

相关文档