行为治理正在取代身份管理:读懂 Akamai 的「Agent 威胁版图」

·阅读约11分钟·Evergreen Tools Team

Akamai 发布了第 12 个年头的《互联网现状》(SOTI)安全报告,题为《速度、规模与非人身份:Agent 威胁版图》,面向 CISO 读者。报告的核心判断很直接:保障现代企业已经从「为人做身份与访问管理」演变成「对自主非人实体做行为治理」。报告点出两个关键难题——给自主 Agent 设定护栏很难,而 AI 模型发现漏洞的速度往往超过人类的补丁周期。本文梳理报告中的关键数据,并给出由此推出的工程控制。

一、数据:风险换了主角

报告中最容易被引用的是三个数字。第一,超过 40% 的企业用户在设备上安装了 AI 驱动的浏览器扩展,而这些扩展里有四分之一在 12 个月内变更过权限——也就是说,昨天你批准的那个「只读摘要」工具,今天可能已经能读你所有的页面。第二,超过 6% 的聊天机器人对话包含敏感信息,主要是个人身份信息;相关报道进一步指出,其中相当一部分交互通过未受管的个人账号发生。第三,Akamai 明确指出攻击者正在跟随企业一起转向 Agentic AI:API 攻击的形态正从传统的 Web 攻击转向基于行为的威胁。

# Nonhuman identity: scope an agent the way you would scope a
# contractor, not the way you scope the employee who hired it.
# Broad inherited permissions are what turn a prompt injection into a breach.

AGENT_SCOPES = {
    # Least privilege per agent, per resource. No wildcards on data.
    "invoice-agent": ["invoices:read", "vendors:read", "erp:write:invoices"],
    "support-agent": ["kb:read", "tickets:read", "tickets:write:notes"],
    "browser-agent": ["web:fetch"],              # no cookie jar, no saved sessions
}

def authorize(agent_id: str, action: str, resource: str) -> bool:
    allowed = AGENT_SCOPES.get(agent_id, [])
    if action not in allowed:
        audit("denied_scope", agent=agent_id, action=action, resource=resource)
        return False
    # Scopes are per-agent and per-session; never accumulate across turns.
    return True
非人身份治理

风险从人的身份管理转向自主非人实体

二、为什么「行为治理」取代了「身份管理」

传统 IAM 的前提是主体稳定:人有一套权限,权限变化是低频事件,审计可以按季度做。Agent 打破了这个前提。模型发现漏洞的速度常常快过人类的补丁周期(这是报告的第二个核心发现),而 Agent 本身的能力边界又取决于每一次提示词与上下文——昨天只能读工单的助手,今天因为多接了一个 MCP 服务器就能写数据库。因此控制的落点必须从「你是谁」移到「你在做什么」。示例 4 把这一点写成行为策略:读操作每小时 120 次是基线,超过四倍就要求加强认证,客户数量超过六倍就限流并告警——这正是批量导出数据的经典形状。Akamai 报告中「约 61% 的 2025 年 API 攻击涉及未授权工作流与异常活动,2024 年这一比例是 30%」这一变化,恰好说明攻击已经住在行为里。

// The browser is the new unprotected workspace. If you cannot list the
// extensions, you cannot answer "who can read this page". Inventory first,
// then constrain what an extension may change about itself.

const reviewQueue = await endpointAgent.query({
  kind: "browser_extension",
  where: {
    flags_ai_powered: true,
    permissionChangeWithinDays: 365,     // Akamai found 25% changed in 12 months
  },
  fields: ["host", "user", "extensionId", "permissionsBefore", "permissionsAfter",
           "knownCveCount"],
});

for (const ext of reviewQueue) {
  const risky =
    ext.permissionsAfter.includes("<all_urls>") ||
    ext.permissionsAfter.includes("debugger") ||
    ext.knownCveCount > 0;                // extensions carried ~60% higher CVE risk
  await ticket({ ext, severity: risky ? "high" : "review", action: "scope_or_remove" });
}

三、浏览器:被忽视的工作区

报告把浏览器称为「关键且未受监控的攻击面」。原因不难理解:Agent 要在 Web 上做事,浏览器扩展就成了它的手和眼,而扩展的权限模型远比后端服务宽松。示例 2 给出务实的处理顺序——先清点,再收敛。查询条件里带上「是否被标记为 AI 驱动」和「一年内是否变更过权限」,这两个条件直接对应报告里 40% 与 25% 的数字。判定为高风险的标准也很简单:拿到了全站访问权限、拿到了调试器权限,或者本身带着已知 CVE。相关报道提到 AI 扩展相较于普通扩展在已知 CVE 风险上高出约 60%,这把「先清点」从合规动作变成了风险动作。

# Chatbot sessions are an exfiltration channel that no DLP rule saw coming.
# 6% of conversations on enterprise devices contain sensitive data, and
# about half of those interactions happen through personal accounts.
# Decide the rule once, then enforce it before the prompt leaves the device.

SENSITIVE = (
    r"(?i)(account|invoice|card)[_ -]?(no|number)[: ]?[0-9]{6,}",
    r"(?i)aws_secret_access_key[ =:]+[A-Za-z0-9/+=]{40}",
    r"[0-9]{3}-[0-9]{2}-[0-9]{4}",
)

def inspect_prompt(prompt: str, account_type: str) -> dict:
    hits = [p for p in SENSITIVE if re.search(p, prompt)]
    if hits and account_type == "personal":
        # Personal accounts are unmonitored; do not let corporate data in.
        return {"action": "block", "why": "corporate data via personal account"}
    if hits:
        return {"action": "redact_then_send", "patterns": len(hits)}
    return {"action": "allow"}
浏览器成为未受管的工作区

40% 以上企业用户装了 AI 扩展,25% 一年内改过权限

四、对话是新的外泄通道

超过 6% 的企业设备对话包含敏感数据,这个数字的真正含义是:DLP 规则的历史盲区。过去的 DLP 盯的是邮件、上传和剪贴板,很少把「你往聊天框里粘了什么」当作出网事件。示例 3 的处理方式值得借鉴:把敏感模式集中定义,然后按账号类型分流——个人账号不被监控,因此绝不允许企业数据经由它出去;企业账号则允许先脱敏再发送。这里的关键不是正则写得多完美,而是把「个人账号」当成一条独立的、默认拒绝的路径。示例 5 则把同样的思路反过来用在 Agent 身上:定期做一次「越权可达性」测试,让每个非人身份去试着访问它无权访问的数据,预期结果是拒绝。

# Agents discover vulnerabilities faster than human patch cycles close them.
# That is Akamai's second headline finding. Treat "new CVE published" as an
# event with a deadline, and let the inventory drive who gets paged.

def patch_deadline(cve: dict) -> dict:
    # Gateways, MCP servers and browser extensions that agents can reach
    # get an SLA proportional to exploitability, not to convenience.
    days = 3 if cve["actively_exploited"] else 7 if cve["cvss"] >= 9.0 else 30
    owners = inventory.owners_of(cve["package"], kinds=("agent", "mcp", "extension"))
    return {"cve": cve["id"], "dueInDays": days, "owners": owners}

def sweep(cves):
    for cve in cves:
        d = patch_deadline(cve)
        if not d["owners"]:
            # Unowned is worse than unpatched: nobody will ever patch it.
            escalate("orphan dependency reachable by agents: " + cve["id"])
        else:
            notify(d["owners"], d)

五、补丁周期追不上模型

报告的另一半是速度问题:模型发现漏洞比人类修补漏洞更快。示例 4 之外,示例 4 前面的第三个示例把这件事写成 SLA:正在被主动利用的漏洞 3 天、CVSS 9.0 以上 7 天、其余 30 天,并且把「谁能接触到这个依赖」作为派单依据——Agent、MCP 服务器、浏览器扩展都算在内。这里有一个容易被忽略的工程细节:没有归属方的依赖比未修补的依赖更危险,因为没有人会去修它,所以示例里对「孤儿依赖」直接升级处理。这其实与示例 1 的非人身份最小权限相呼应:当你无法确定一个 Agent 该有什么权限时,正确的默认值是没有权限。

// Behavioral governance means policy on what an agent does, not only on
// who it is. An agent that suddenly starts reading an unusual number of
// records is a signal even if its credentials are perfectly valid.

const behavioralPolicy = {
  agentId: "support-agent",
  baseline: { readsPerHour: 120, distinctCustomersPerHour: 40, exportsPerDay: 0 },
  rules: [
    { when: "readsPerHour > 4 * baseline.readsPerHour", then: "step_up_auth" },
    { when: "distinctCustomersPerHour > 6 * baseline.distinctCustomersPerHour",
      then: "throttle_and_notify" },     // classic bulk-export shape
    { when: "newEgressHost and !allowlisted", then: "block" },
  ],
  evidence: ["traceId", "tool", "resourceIds", "promptHash"],  // keep the why
};

// 61% of API attacks in 2025 involved unauthorized workflows and abnormal
// activity, up from 30% in 2024. Behaviour is where the attack now lives.
对话中的敏感数据

超过 6% 的聊天对话包含敏感信息

六、给安全团队的落地顺序

第一,为每个 Agent 分配独立身份与最小权限作用域,绝不继承发起人的全会话权限(示例 1)。第二,把浏览器扩展与 MCP 服务器并入同一份资产清单,清点优先级按「AI 驱动」与「一年内权限变更」排序(示例 2)。第三,为对话通道定义敏感数据策略,个人账号路径默认拒绝(示例 3)。第四,把补丁 SLA 与可达性挂钩,把孤儿依赖升级处理(示例 4)。第五,建立行为基线,对偏离基线的 Agent 采取加强认证、限流或阻断(示例 5)。第六,定期做越权可达性回归,让「不可达」成为可被验证的断言而不是假设(示例 6)。Akamai 的 CSO Boaz Gelbord 把这轮变化概括为「一切、无处不在、同时发生」的三重威胁:内部 AI 使用、AI 进入客户产品、以及 AI 驱动的攻击。控制手段不必同样宏大,但必须同样具体。

📌 常见问题 FAQ

Akamai 这份报告的全名是什么?

报告名为《速度、规模与非人身份:Agent 威胁版图》(Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape),属于 Akamai 第 12 年的《互联网现状》(SOTI)安全报告系列。

「行为治理」和传统身份管理差在哪?

传统 IAM 假设主体稳定、权限低频变化;Agent 的能力随提示词与上下文变化,因此控制点需要从「你是谁」转向「你在做什么」,用行为基线来识别异常。

报告提到的浏览器风险有多具体?

超过 40% 的企业用户安装了 AI 驱动的浏览器扩展,其中 25% 在 12 个月内变更过权限。Akamai 将其称为关键且未受监控的攻击面。

聊天机器人泄漏数据的情况严重吗?

超过 6% 的聊天机器人对话包含敏感信息,主要为个人身份信息;相关报道指出其中相当一部分交互通过未受管的个人账号发生。

报告给 CISO 的核心建议是什么?

为非人身份建立独立的身份与最小权限、把浏览器扩展与 MCP 服务器纳入统一资产清单、为对话通道设定敏感数据策略、按可达性制定补丁 SLA,并对 Agent 行为建立基线与异常响应。