A win, a miss and a path to stronger digital authentication一次胜利,一次失败,以及通往更强大的数字认证之路
The NCSIP introduces a dedicated segment for policy reviews, ensuring an adaptive strategy that remains in sync with an evolving cybersecurity landscape.

This month, the Biden Administration unveiled the National Strategy Implementation Plan for the National Cybersecurity Strategy , which calls for transformative changes in managing the U.S. digital environment, prioritizing security and resilience across public and private sectors and balancing investments between future development and addressing immediate threats.
The plan represents a departure from the previous strategy criticized for lack of specificity in action. The Digital Forensic Research Lab at the Atlantic Council noted that the current blueprint downscaled ambitious initial objectives, resulting in a simplified and potentially less effective approach. Of most concern is the need for a comprehensive digital identity solution . This is further complicated by the US government’s adoption of a zero-trust architecture strategy , which will undoubtedly alter cybersecurity measures for government contractors and other partnering organizations—particularly those outside on-premise infrastructure.
The strategy’s failure to include a strong digital identity solution is a significant setback, mainly since ZTA is limited to Domain Name System and Hypertext Transfer Protocol. Utilizing Open-Source Software to develop AI-empowered authentication offers a promising long to term solution to ZTA for creative user authentication. By adopting this approach, the government can achieve robust digital identification, enhancing transparency, flexibility, and real-time threat detection for a more secure digital ecosystem.
Open-source software
The NCSIP delivers a more detailed approach and designates responsibilities for government stakeholders, encompassing sixty-five federal initiatives to safeguard American employment, combat cybercrime, and enhance domestic cybersecurity expertise, utilizing legislative support from the Inflation Reduction Act and CHIPS & Science Act .
Moreover, the plan places increased cybersecurity standard compliance responsibility on the private sector, guided by the Office of the National Cyber Director. Notably, the NCSIP introduces a dedicated segment for regular policy reviews, ensuring an adaptive strategy that remains in sync with the ever-changing cybersecurity landscape, a long-awaited measure advocated by experts.
One essential aspect of the plan that deserves highlighting is the advocacy for Open-Source Software. OSS has been in use by the Department of Defense since 2009 , offering several advantages for government applications , including cost-effectiveness and encouraging open collaboration. OSS operates like an adaptable recipe, freely available for anyone to use, modify, improve, and share.
A key benefit is that it does not require licensing fees, potentially leading to lower maintenance and support costs, which align well with government budgets. Furthermore, OSS’s flexibility and customization capacity are critical for addressing specific governmental needs, especially in complex projects faced by the intelligence community and the DoD.
As the government increasingly integrates artificial intelligence platforms, leveraging OSS can lead to more efficient data processing and safeguarding of sensitive networks. For instance, institutions can significantly enhance Intrusion Detection Systems, Intrusion Prevention Systems, and proxies by utilizing network simulators or machine learning platforms derived from OSS and customized to meet specific government needs.
While OSS has significant advantages, it also has potential challenges . These can include hidden costs associated with training, support, and integration, the need for substantial resources and expertise to secure and review the code, potential fragmentation, and slower or less predictable development timelines. Organizations should consider the decision to use OSS on a case-by-case basis, taking into account their specific requirements and available resources.
By striking the right balance, OSS can develop resilient digital identity solutions and improve cyber defense measures.
Digital identity plays a critical role in cybersecurity. Most security breaches occur due to flaws in digital identity processes and tools. Custom-made identity processes and legacy digital identity software from the early 2000s often open avenues for malicious activities and are inefficient. Therefore, there needs to be a comprehensive digital identity solution.
The recent incident involving Chinese hackers penetrating US government email accounts , as reported by Microsoft, serves as a stark reminder of the critical importance of digital identity. Implementing an effective ZTA must extend beyond on-premise infrastructure and include robust digital identity solutions (e.g., digital signature, public-key encryption, and key-establishment algorithms) capable of resisting state-backed hackers and being available to users worldwide. Furthermore, it must be capable of protecting sensitive government information well into the foreseeable future, including after the advent of quantum computers.
Between 2019 and 2021, account takeover attacks surged by 307% , demonstrating the increasing sophistication of cybercrimes. These attacks not only damage public trust but also cause substantial financial harm. Cybercriminals are exploiting AI to bypass traditional authentication schemes using methods like credential stuffing and creating deep fakes. However, harnessing AI within the ZTA can provide valuable security benefits, like real-time threat detection, to ensure a proactive approach to authentication.
Moreover, this solution could leverage improving further digital security opportunities, such as decentralized networks and quantum key distribution. Digital identity is not only about security; it also enhances user experience and productivity while reducing time and costs. It’s a necessary tool for enabling secure and easy interaction in the digital world for both individuals and organizations.
A robust digital identity solution is not a luxury ; it is a requisite to ensure operational security and prevent unauthorized access, especially in a complex and interconnected environment.
OSS and AI integration
The zero trust maturity model operates on the principle of not implicitly trusting any network and revolves around dynamic risk-based authentication, continuously adjusting access controls based on real-time threat assessments. Adopting zero-trust security, as emphasized in President Biden’s Executive Order 14028 , is an urgent necessity with the rise of remote work and increasing breaches. Zero trust minimizes the attack surface and prevents unauthorized lateral movement within networks but also hinders network access.
Building on OSS with AI can achieve the robust digital solutions needed within the Zero Trust model to defend against hacking attempts while allowing broader user access. OSS provides transparency and flexibility to the cybersecurity ecosystem, with publicly accessible source code enabling continuous peer review and rapid vulnerability identification. This transparency and flexibility complement AI integration, which enhances real-time IDS, IPS, and adaptive response capabilities. By processing vast data, AI algorithms identify anomalies and potential cyber threats which compromise device and network integrity.
Leveraging AI-driven risk analysis, contextual factors like user location, device health, and behavior patterns dynamically modify access privileges. For example, accessing sensitive data from an unusual location may prompt the system to require additional authentication methods. The convergence of OSS and AI facilitates continuous learning from past incidents, current trends, and emerging attack vectors, empowering the system to maintain a proactive and agile defense strategy. Real-time analysis of cyber trends and emerging threats ensures organizations can swiftly adapt to evolving techniques, bolstering their cybersecurity resilience.
Embracing ZTA is a necessity for protecting sensitive data, critical infrastructure, and national interests. The transparency and flexibility of OSS form a strong foundation for security, while AI-driven capabilities empower the system to detect and respond to cyber threats in real time. By prioritizing digital identity solutions and leveraging the full potential of AI and OSS, a secure and resilient digital ecosystem will further strengthen cyber security.
Maj. Nicholas Dockery is a research fellow for the Modern Warfare Institute. He is also a Downing Scholar, an active duty special forces officer, and a contributor to the Irregular Warfare Initiative. The views expressed are those of the author(s) and do not reflect the official position of the United States Military Academy, Department of the Army, or Department of Defense.
本月,拜登政府公布了《国家网络安全战略实施计划》,该计划呼吁对美国数字环境的管理进行变革性改变,优先考虑公共和私营部门的安全性和韧性,并在未来发展和应对当前威胁之间取得投资平衡。
该计划标志着与之前因缺乏具体行动方案而备受诟病的战略的决裂。大西洋理事会数字取证研究实验室指出,目前的蓝图缩减了最初雄心勃勃的目标,导致方案简化,但可能效果也更差。最令人担忧的是,我们需要一个全面的数字身份解决方案。美国政府推行的零信任架构战略进一步加剧了这一问题的复杂性,这无疑将改变政府承包商和其他合作机构(尤其是那些位于企业内部基础设施之外的机构)的网络安全措施。
该战略未能纳入强大的数字身份解决方案是一个重大缺陷,主要原因是零信任身份验证 (ZTA) 仅限于域名系统 (DNS) 和超文本传输协议 (HTTP)。利用开源软件开发人工智能赋能的身份验证系统,为 ZTA 提供了一种极具前景的长期解决方案,可用于创新型用户身份验证。通过采用这种方法,政府可以实现强大的数字身份识别,增强透明度、灵活性和实时威胁检测能力,从而构建更安全的数字生态系统。
开源软件
NCSIP 提供了一种更详细的方法,并指定了政府利益相关者的责任,涵盖了 65 项联邦举措,旨在保障美国就业、打击网络犯罪和提高国内网络安全专业知识,并利用《通货膨胀削减法案》和《CHIPS & 科学法案》的立法支持。
此外,该计划在国家网络安全总监办公室的指导下,加大了私营部门遵守网络安全标准的责任。值得注意的是,国家网络安全和基础设施保护计划(NCSIP)设立了专门的定期政策审查环节,确保战略能够适应不断变化的网络安全形势,这是专家们期待已久的一项举措。
该计划中一个值得重点强调的重要方面是倡导开源软件。自2009年以来,美国国防部一直在使用开源软件,它为政府应用带来了诸多优势,包括成本效益和鼓励开放协作。开源软件就像一份可灵活调整的食谱,任何人都可以免费使用、修改、改进和共享。
一项关键优势在于它无需支付许可费,从而可能降低维护和支持成本,这与政府预算非常契合。此外,开源软件的灵活性和定制能力对于满足特定的政府需求至关重要,尤其是在情报界和国防部面临的复杂项目中。
随着政府日益整合人工智能平台,利用开源软件(OSS)可以提高数据处理效率并加强敏感网络的安全防护。例如,机构可以通过使用源自开源软件并根据特定政府需求定制的网络模拟器或机器学习平台,显著提升入侵检测系统、入侵防御系统和代理服务器的性能。
开源软件虽然优势显著,但也存在一些潜在挑战。这些挑战包括培训、支持和集成方面的隐性成本,需要大量资源和专业知识来保护和审查代码,可能出现代码碎片化,以及开发进度缓慢或难以预测。企业应根据自身具体情况,结合自身需求和可用资源,逐案考虑是否采用开源软件。
通过取得适当的平衡,OSS 可以开发出具有弹性的数字身份解决方案,并改进网络防御措施。
数字身份在网络安全中扮演着至关重要的角色。大多数安全漏洞都是由于数字身份流程和工具的缺陷造成的。定制的身份流程和2000年代初期的传统数字身份软件往往效率低下,容易受到恶意攻击。因此,我们需要一个全面的数字身份解决方案。
据微软报道,近期中国黑客入侵美国政府电子邮件账户的事件,再次凸显了数字身份的重要性。实施有效的零威胁架构(ZTA)必须超越本地基础设施,包含强大的数字身份解决方案(例如数字签名、公钥加密和密钥建立算法),这些方案不仅能够抵御国家支持的黑客攻击,还能供全球用户使用。此外,该架构还必须能够在可预见的未来,包括量子计算机出现之后,持续保护敏感的政府信息。
2019年至2021年间,账户盗用攻击激增307%,表明网络犯罪的复杂性日益增加。这些攻击不仅损害了公众信任,也造成了巨大的经济损失。网络犯罪分子正利用人工智能技术,通过撞库攻击和深度伪造等手段绕过传统的身份验证机制。然而,在零信任账户(ZTA)中应用人工智能技术,可以带来诸多安全优势,例如实时威胁检测,从而确保采取主动的身份验证方式。
此外,该解决方案还能利用去中心化网络和量子密钥分发等技术,进一步提升数字安全。数字身份不仅关乎安全,还能提升用户体验和工作效率,同时降低时间和成本。对于个人和组织而言,它都是在数字世界中实现安全便捷交互的必备工具。
强大的数字身份解决方案并非奢侈品;它是确保运营安全和防止未经授权访问的必要条件,尤其是在复杂且相互关联的环境中。
OSS和AI集成
零信任成熟度模型基于不默认信任任何网络的原则,其核心是动态的、基于风险的身份验证,并根据实时威胁评估不断调整访问控制。正如拜登总统在第14028号行政命令中所强调的,随着远程办公的兴起和数据泄露事件的日益增多,采用零信任安全策略已迫在眉睫。零信任策略能够最大限度地减少攻击面,防止网络内部未经授权的横向移动,但同时也限制了网络访问。
基于开源软件(OSS)和人工智能(AI)的构建,能够实现零信任模型所需的强大数字化解决方案,有效抵御黑客攻击,同时允许更广泛的用户访问。开源软件为网络安全生态系统提供了透明度和灵活性,其公开可访问的源代码支持持续的同行评审和快速漏洞识别。这种透明度和灵活性与人工智能集成相辅相成,增强了实时入侵检测系统(IDS)、入侵防御系统(IPS)和自适应响应能力。通过处理海量数据,人工智能算法能够识别异常情况和潜在的网络威胁,从而保障设备和网络的完整性。
利用人工智能驱动的风险分析,系统会根据用户位置、设备健康状况和行为模式等上下文因素动态调整访问权限。例如,从异常位置访问敏感数据可能会触发系统要求额外的身份验证方式。开源软件(OSS)与人工智能的融合有助于系统从过往事件、当前趋势和新兴攻击途径中持续学习,从而使其能够保持主动且敏捷的防御策略。对网络趋势和新兴威胁的实时分析确保组织能够快速适应不断演变的技术,从而增强其网络安全韧性。
拥抱零风险架构 (ZTA) 对于保护敏感数据、关键基础设施和国家利益至关重要。开源软件 (OSS) 的透明性和灵活性为安全奠定了坚实的基础,而人工智能驱动的功能则使系统能够实时检测和响应网络威胁。通过优先发展数字身份解决方案并充分利用人工智能和开源软件的潜力,构建一个安全且具有弹性的数字生态系统将进一步加强网络安全。
尼古拉斯·多克里少校是现代战争研究所的研究员,同时也是唐宁学者、现役特种部队军官以及非常规战争倡议的撰稿人。文中观点仅代表作者个人立场,并不反映美国军事学院、陆军部或国防部的官方立场。