← 返回简报
logo
全球防务头条
Global Defense Headlines
2026年4月17日
其他 一般 安全周刊 1 分钟阅读

安全专家呼吁美政府与私企深度协作以对抗国家级网络战

安全周刊 专注于网络安全与防御技术的专业媒体
安全专家呼吁美政府与私企深度协作以对抗国家级网络战
摘要
安全专家近期发出警告,指出在应对日益精密且高强度的网络战争时,美国政府单纯依靠公共部门的防御模式已难以为继。由于现代数字化基础设施主要由私营科技公司构建,政府必须深度整合私企的技术实力才能有效维护国家安全。当前的网络威胁在规模和复杂度上已显著提升,约87%的入侵案例涉及跨网络、云平台和身份系统的多重攻击面,使得单一层面的防御措施形同虚设。特别是通过供应链和第三方服务商发起的攻击,已成功渗透进美国财政部等核心政府机构,显示出攻击面已无限扩张。专家强调,理想的防御和进攻态势需要建立政府与私营部门之间的风险管理协同机制。只有实现信息共享与防御联通,才能在高强度网络战争中保护国家关键信息资产。这种公私协作模式被视为未来对抗敌对国家系统性网络攻击、提升整体韧性的必然选择。
中文译文

网络安全是攻击者与防御者之间的竞赛。长期以来,政府一直在孤军奋战,而攻击者频繁锁定公共部门实体,在几乎没有阻力的情况下发起具有国家影响的攻击。尽管有建立基准控制的规则和条例,但攻击仍在继续定义日益增长的威胁格局。严峻的现实是,威胁面已经超出了政府能够切实防御的范围。

政府旨在保护的数字基础设施是私营公司的产物。国家自身能够保障的安全有限,这意味着重点必须转向与私营部门的密切合作。为什么理想的防御和进攻态势需要政府更协作的努力?

首先,网络威胁的规模和复杂性在上升。现代网络攻击在频率、规模和成熟度上都高出许多。帕洛阿尔托网络公司发现,在750多个事件响应案例中,87%的入侵针对多个攻击面,从终端和网络到云基础设施、软件服务(SaaS)、应用和身份认证。入侵在连接的系统中横向传播,因此当攻击者可以在同一行动中通过多个切入点转移时,仅防御好一层是不够的。

其次,日常依赖支撑的攻击面正在扩大。现在的攻击已经超出了组织的运作边界,包括云平台、API、供应商和托管服务提供商。这些第三方依赖扩展了攻击面,为攻击者提供了更多利用途径。对远程支持工具的攻破曾使攻击者能够进入美国财政部的多个办公室,这证明了这种威胁的现实性。

英文原文
收起原文

Cybersecurity is a contest between attackers and defenders. For far too long, governments have been defending their turf alone while attackers frequently target public-sector entities with little to no resistance, launching attacks with national ramifications. Despite rules and regulations meant to establish baseline controls, attacks continue to define a growing threat landscape. The harsh reality is that the threat surface has grown wildly beyond what governments can realistically defend.

The digital infrastructure that governments aim to secure is a product of private companies. There are limits to what the state can secure on its own, which means the focus must shift to closer collaboration with the private sector.

Let’s take a closer look at why an ideal defensive and offensive posture for risk management should entail a more collaborative effort from the government.

Rise in the scale and complexity of cyberthreats

Modern cyberattacks have gone many notches higher in terms of cadence, scale, and sophistication. Such attacks do not depend on a single vector. Palo Alto Networks found that 87% of intrusions across 750+ incident response cases targeted multiple attack surfaces, from endpoints and networks to cloud infrastructure, SaaS, apps, and identity. Intrusions spread laterally across connected systems, so defending one layer well isn’t enough when attackers can pivot through multiple access points in the same campaign.

Growing attack surface underpinned by everyday dependencies

Years ago, the attack surface felt like an attack on the organization’s operational perimeter. Today’s attacks have moved beyond this perimeter to include the functional elements of any organization, including cloud platforms, APIs, vendors and managed services providers. These third-party dependencies broaden the attack surface, giving cyber attackers more avenues to exploit. A compromise of a remote support tool enabled attackers to access multiple U.S. Treasury Department offices, an example of how third-party access can become the easiest entry point.

Technology ownership controlled by private entities

There was a time when major technology shifts and advancements were a direct outcome of research funded by different government entities. Examples of that include the origins of the Internet, global positioning systems (GPS), solar energy and many others. But things have changed, and it is the private sector that now drives technological advancements. Critical digital infrastructure is overwhelmingly built and operated by private entities, and the government doesn’t have total control over all its operational levers. This demands a change in thinking, requiring them to partner with the private sector to secure the infrastructure on which a country depends.

Cybercrime has gone industrial and is very persistent

Cybercrime is an industry with different specializations, services, tooling, and repeatable playbooks. And this industry is decentralized, meaning arresting

🔗
原文链接:https://www.securityweek.com/government-cant-win-the-cyber-war-without-the-private-sector/