




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
TechnicalInsights:How
ChatGPTCanImproveSecurityOperations
DennisXu
?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.Thispublicationmaynotbereproducedordistributedinanyform
withoutGartner'spriorwrittenpermission.ItconsistsoftheopinionsofGartner'sresearchorganization,whichshouldnotbeconstruedasstatementsoffact.Whiletheinformationcontainedinthispublicationhasbeenobtainedfromsourcesbelievedtobereliable,Gartnerdisclaimsallwarrantiesastotheaccuracy,completenessoradequacyofsuchinformation.AlthoughGartnerresearchmayaddresslegalandfinancialissues,Gartnerdoesnotprovidelegalorinvestmentadviceanditsresearchshouldnotbeconstruedorusedassuch.YouraccessanduseofthispublicationaregovernedbyGartner’sUsagePolicy.Gartnerpridesitselfonitsreputationforindependenceandobjectivity.Itsresearchisproducedindependentlybyitsresearchorganizationwithoutinputor
influencefromanythirdparty.Forfurtherinformation,see"GuidingPrinciplesonIndependenceandObjectivity."
2023
Incand/oritsaffiliates
reservedGartnerisaregisteredtrademarkofGartner,anditsaffiliates
Agenda
1WhatIsGenerativeAI?
2WhatIsChatGPT?
3ChatGPTRisks
4UnderstandingWhereItFitsinSecOps
5SampleSecOpsUseCases
6PlanningforChatGPTUsageinSecOps
7TheFutureofChatGPTandSecOps
QuickIntroduction
toChatGPT
4?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
GPTmodelsaretransformer-based
deeplearningneural
networkarchitectures.
5?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
WhatIsGenerativeAI?
ChatGPT
AnOpenAIservicethatincorporatesaconversationalchatbotwithLLMtocreatecontent.Itwastrainedonafoundational
modelofbillionsofwordsfrommultiplesourcesandwasthenfine-tunedbyreinforcementlearningfromhumanfeedback.
LargeLanguageModels(LLM)
FoundationModels
GenerativeAI(GAI)
AIthatistrainedonvastamountsoftexttointerpretandgeneratehuman-liketextualoutput.
Largemachinelearningmodels.Theyaretrainedonabroadsetofunlabeleddata,adaptedtoawiderangeofapplicationswithfine-tuning.
AItechniquesthatlearnfromarepresentationofartifacts
fromdataandmodelswhichitusestogeneratenewartifacts.
Source:Gartner
6?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
WhatIsChatGPT?
ChatGPT
GPT-3
Prompt
Whatsecurityoperation
centertaskscanChatGPThelpwith?
7?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
WhatIsChatGPT?(Continued)
Textinput/output
Inputfilteringandprompt
preparation
(andconversation)
Outputacceptabilityfilteringandconversationpreparation
Sessioncontext
ClosedGPT-3model
Reinforcementlearningandhumanfeedbacktraining
RLHF
ClosedversionofGPT-3trainingdataandprocess
8?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
ChatGPTRisks
Note:ExamplesinthispresentationweregeneratedusingOpenAI’sGPT-3.5andareforillustrativepurposes
only.GPT-4isavailableforChatGPTbutisonlyavailablewithaChatGPTPlussubscriptioncurrently.
9?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
WhereChatGPTFits
WithSecOpsand
SampleUseCases
10?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
?
HowDoesChatGPTFitIntoSecOps?
?DetectionEngineering
?IncidentResponse
?VulnerabilityManagement
?AttackSurfaceManagement
凸
?Training
?OperationalizinganSOC
?MeasuringanSOC
SOC=SecurityOperationCenter
11?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
SampleUseCases:
DetectionEngineering
Analyzethislogmessage:
May116:17:43owl
sshd[9024]:Acceptedpublickeyforroot
from
01
port37384ssh2
12?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.andits
SampleUseCases:
DetectionEngineering
Createregular
expressionstoparsethislogmessage.
Validation:Useatoollike
/
toshowthatregexsuggestionswillparsethelog.
13?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
SampleUseCases:
DetectionEngineering
Createasigmarulethatwilldetect
bruteforceloginattempts
onWindows.
Validation:UseUncoder.IOtoValidateSigmaRules
14?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
Turnthis
sigma
ruleintoaSplunkquery.
Validation:Thiscanbemoredifficulttovalidate,butitispossiblewith
simulatingloginfailures.
15?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.Gartner
SampleSecOpsUseCases—IncidentResponse
?ScriptUnderstanding
?Examples:
?Analyzethefollowingscript:<code>
?Doesthefollowingcodehaveanyvulnerabilities:<code>
?Validation:PeopleandProcess
?ResponsePlaybookCreation
?Examples:
?Createastep-by-stepplaybookonhowtoinvestigateransomwareonWindows
?Createastep-by-stepplaybook,withtoolsandcommandstorun,onhowtoinvestigateransomwareonWindows
?Validation:PeopleandProcess
16?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
SampleSecOpsUseCases—IncidentResponse
?IncidentInvestigationAdvice
?Examples:
?Givenanincidentwith<incident_title>,andincidentdescriptionof<incident_description>,howwouldyousuggestgoingaboutinvestigatingthissituation?
?Validation:PeopleandProcess
17?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
SampleSecOpsUseCases—Training
?TabletopScenarioGeneration
?Examples:
?Createatabletopcybersecurityexercisethatincludesanationstatetryingtohackintoafinancialinstitution
?Validation:People
?NewSecurityAnalysisGuidance
?Examples:
?Helpmeunderstandhowtoanalyzelogdataforsignsofintrusion
?Validation:PeopleandProcess
18?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
Planningfor
ChatGPTUsage
19?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsageinSecOps—
ResetExpectations
?CanMakeUpThings,“Hallucinations”
?NoSilverBullet
?ItCan’tConnecttotheInternet
?Security,PrivacyandGovernanceAreImportant
?DeterminingAccuracyIsNotEasy
–RequiresExperiencedAnalysisofResults
?GeneratesaStartingPoint
20?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsagein
SecOps—Governance
?EstablishProperUsageRules
–GiveUsersTraining
–OnlySeniorStaffCanUseIt
–JuniorStaffCanUseItUnderSupervision
21?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsageinSecOps—
Governance(Cont’d)
?DefineDataSanitizationStandards–PII
–PHI
–IPAddresses
–Usernames
–Geolocations
PII=PersonallyIdentifiableInformationPHI=ProtectedHealthInformation
22?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsage
—PickUseCases(UCs)
?IdentifyyourcommonSecOpsUCs—donotpicktime-sensitiveones
?IdentifyUCsnotdependentonsensitiveorcorporatedata
–UseOpenAI’sChatGPTforexperimentation
?RefineUCs,possiblyusingpromptengineering
AllrightsreservedGartnerisa
trademarkofGartner,Incanditsaffiliates
PlanningforChatGPTUsageinSecOps—
EstablishOversight/Monitoring
?MentorandMonitorJuniorStaff
–ReviewWorkLogs,Reports,etc.
?TrackAccuracy
–CreateKnowledgeBaseof
ChatGPTPromptsandResponsesWithAccuracyAssessment
–RefineUseCasesasNeeded,PromptEngineering
24?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsagein
SecOps—ValidateResults
?EstablishaValidationMindset
?IdentifyToolstoAidinValidation
–People
–Process
–Technology
?ContinuallyValidateResults,EarlyandOften
25?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
PlanningforChatGPTUsageinSecOps—Putting
ItAllTogether
IdentifyYourSecOpsUCs
Noncorporate-SpecificUCs
RefineUCs
EstablishProperUsageRules
EstablishDataSanitizationStandards
Establish
ValidationMindset
IdentifyToolstoAidinValidation
Continually
ValidateResults
MentorJuniorStaff
MonitorJuniorStaff
TrackAccuracy,RefineUCs
EstablishOversight/Monitoring
EstablishSomeGovernance
Reset
Expectations
PickUseCases(UC)
ValidateResults
NoSilverBullet
ItCan’tConnecttotheInternet
CanMakeUp
Things,
“Hallucinations”
Determining
AccuracyIsNot
Easy
GeneratesaStartingPoint
26?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
FutureofChatGPT
andSecOps,andCommonPitfalls
27?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
TheFutureofChatGPTandSecOps
?ItWillGetBetterOverTime
?WatchforGenerativeAIFromExistingProviders
?MoveAwayFromChatGPTInterfaceandTowardNativeVendorIntegration,e.g.,
MicrosoftSecurityCopilot,andSoOn
?DemocratizationofSecOps
?HelpReduceMTTR,PossiblyMTTD
?GenerateThreat-HuntingHypotheses
MTTR=MeanTimetoRecoverMTTD=MeanTimetoDetect
Pitfalls
?ExposingPrivate/SensitiveDatainChatGPTInterface
?JumpinginRatherThanExecutingaPhasedApproach
?NotValidatingResults
?UsingTime-SensitiveorReal-TimeUseCases
29?2023Gartner,Inc.and/oritsaffiliates.Allrightsreserved.GartnerisaregisteredtrademarkofGartner,Inc.anditsaffiliates.
Recommendations
oEstablishagovernanceandoversightprocessforthe
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 鄉(xiāng)村文化旅游開發(fā)運(yùn)營(yíng)合作協(xié)議
- 綜合金融服務(wù)領(lǐng)域金融創(chuàng)新產(chǎn)品開發(fā)計(jì)劃
- 新能源汽車充電設(shè)施建設(shè)與管理手冊(cè)
- 陜西2025年陜西楊凌示范區(qū)事業(yè)單位招聘15人筆試歷年參考題庫附帶答案詳解
- 2022年執(zhí)業(yè)藥師考試《中藥學(xué)專業(yè)知識(shí)(一)》真題及解析
- 2021年全國(guó)一級(jí)建造師執(zhí)業(yè)資格考試試卷 《民航機(jī)場(chǎng)工程管理與實(shí)務(wù)》
- 大環(huán)內(nèi)酯類抗生素聯(lián)合甲潑尼龍治療兒童肺炎支原體肺炎的臨床療效分析
- 創(chuàng)業(yè)計(jì)劃書:文檔形式與關(guān)鍵要素
- 教視網(wǎng)安全教育
- 實(shí)驗(yàn)室月工作總結(jié)
- 食品行業(yè)安全監(jiān)管與溯源方案
- 書籍設(shè)計(jì)出版合同范本
- 2025年法律文書考試試題及答案
- 2025年公園綠化樹木維護(hù)合同
- 2023年高考真題全國(guó)乙卷物理試卷
- 運(yùn)梁車培訓(xùn)教材
- 節(jié)后復(fù)工復(fù)產(chǎn)安全教育培訓(xùn)資料
- 2023年全國(guó)高考體育單招考試英語卷試題真題(含答案詳解)
- 軸承基礎(chǔ)知識(shí)測(cè)試
- 《體驗(yàn)微視頻拍攝樂趣》第一課時(shí)初中七年級(jí)勞動(dòng)教育課件
- 主水管改造合同范例
評(píng)論
0/150
提交評(píng)論