行为治理正在取代身份管理:读懂 Akamai 的「Agent 威胁版图」
Akamai 发布了第 12 个年头的《互联网现状》(SOTI)安全报告,题为《速度、规模与非人身份:Agent 威胁版图》,面向 CISO 读者。报告的核心判断很直接:保障现代企业已经从「为人做身份与访问管理」演变成「对自主非人实体做行为治理」。报告点出两个关键难题——给自主 Agent 设定护栏很难,而 AI 模型发现漏洞的速度往往超过人类的补丁周期。本文梳理报告中的关键数据,并给出由此推出的工程控制。
一、数据:风险换了主角
报告中最容易被引用的是三个数字。第一,超过 40% 的企业用户在设备上安装了 AI 驱动的浏览器扩展,而这些扩展里有四分之一在 12 个月内变更过权限——也就是说,昨天你批准的那个「只读摘要」工具,今天可能已经能读你所有的页面。第二,超过 6% 的聊天机器人对话包含敏感信息,主要是个人身份信息;相关报道进一步指出,其中相当一部分交互通过未受管的个人账号发生。第三,Akamai 明确指出攻击者正在跟随企业一起转向 Agentic AI:API 攻击的形态正从传统的 Web 攻击转向基于行为的威胁。
# Nonhuman identity: scope an agent the way you would scope a
# contractor, not the way you scope the employee who hired it.
# Broad inherited permissions are what turn a prompt injection into a breach.
AGENT_SCOPES = {
# Least privilege per agent, per resource. No wildcards on data.
"invoice-agent": ["invoices:read", "vendors:read", "erp:write:invoices"],
"support-agent": ["kb:read", "tickets:read", "tickets:write:notes"],
"browser-agent": ["web:fetch"], # no cookie jar, no saved sessions
}
def authorize(agent_id: str, action: str, resource: str) -> bool:
allowed = AGENT_SCOPES.get(agent_id, [])
if action not in allowed:
audit("denied_scope", agent=agent_id, action=action, resource=resource)
return False
# Scopes are per-agent and per-session; never accumulate across turns.
return True风险从人的身份管理转向自主非人实体
二、为什么「行为治理」取代了「身份管理」
传统 IAM 的前提是主体稳定:人有一套权限,权限变化是低频事件,审计可以按季度做。Agent 打破了这个前提。模型发现漏洞的速度常常快过人类的补丁周期(这是报告的第二个核心发现),而 Agent 本身的能力边界又取决于每一次提示词与上下文——昨天只能读工单的助手,今天因为多接了一个 MCP 服务器就能写数据库。因此控制的落点必须从「你是谁」移到「你在做什么」。示例 4 把这一点写成行为策略:读操作每小时 120 次是基线,超过四倍就要求加强认证,客户数量超过六倍就限流并告警——这正是批量导出数据的经典形状。Akamai 报告中「约 61% 的 2025 年 API 攻击涉及未授权工作流与异常活动,2024 年这一比例是 30%」这一变化,恰好说明攻击已经住在行为里。
// The browser is the new unprotected workspace. If you cannot list the
// extensions, you cannot answer "who can read this page". Inventory first,
// then constrain what an extension may change about itself.
const reviewQueue = await endpointAgent.query({
kind: "browser_extension",
where: {
flags_ai_powered: true,
permissionChangeWithinDays: 365, // Akamai found 25% changed in 12 months
},
fields: ["host", "user", "extensionId", "permissionsBefore", "permissionsAfter",
"knownCveCount"],
});
for (const ext of reviewQueue) {
const risky =
ext.permissionsAfter.includes("<all_urls>") ||
ext.permissionsAfter.includes("debugger") ||
ext.knownCveCount > 0; // extensions carried ~60% higher CVE risk
await ticket({ ext, severity: risky ? "high" : "review", action: "scope_or_remove" });
}三、浏览器:被忽视的工作区
报告把浏览器称为「关键且未受监控的攻击面」。原因不难理解:Agent 要在 Web 上做事,浏览器扩展就成了它的手和眼,而扩展的权限模型远比后端服务宽松。示例 2 给出务实的处理顺序——先清点,再收敛。查询条件里带上「是否被标记为 AI 驱动」和「一年内是否变更过权限」,这两个条件直接对应报告里 40% 与 25% 的数字。判定为高风险的标准也很简单:拿到了全站访问权限、拿到了调试器权限,或者本身带着已知 CVE。相关报道提到 AI 扩展相较于普通扩展在已知 CVE 风险上高出约 60%,这把「先清点」从合规动作变成了风险动作。
# Chatbot sessions are an exfiltration channel that no DLP rule saw coming.
# 6% of conversations on enterprise devices contain sensitive data, and
# about half of those interactions happen through personal accounts.
# Decide the rule once, then enforce it before the prompt leaves the device.
SENSITIVE = (
r"(?i)(account|invoice|card)[_ -]?(no|number)[: ]?[0-9]{6,}",
r"(?i)aws_secret_access_key[ =:]+[A-Za-z0-9/+=]{40}",
r"[0-9]{3}-[0-9]{2}-[0-9]{4}",
)
def inspect_prompt(prompt: str, account_type: str) -> dict:
hits = [p for p in SENSITIVE if re.search(p, prompt)]
if hits and account_type == "personal":
# Personal accounts are unmonitored; do not let corporate data in.
return {"action": "block", "why": "corporate data via personal account"}
if hits:
return {"action": "redact_then_send", "patterns": len(hits)}
return {"action": "allow"}40% 以上企业用户装了 AI 扩展,25% 一年内改过权限
四、对话是新的外泄通道
超过 6% 的企业设备对话包含敏感数据,这个数字的真正含义是:DLP 规则的历史盲区。过去的 DLP 盯的是邮件、上传和剪贴板,很少把「你往聊天框里粘了什么」当作出网事件。示例 3 的处理方式值得借鉴:把敏感模式集中定义,然后按账号类型分流——个人账号不被监控,因此绝不允许企业数据经由它出去;企业账号则允许先脱敏再发送。这里的关键不是正则写得多完美,而是把「个人账号」当成一条独立的、默认拒绝的路径。示例 5 则把同样的思路反过来用在 Agent 身上:定期做一次「越权可达性」测试,让每个非人身份去试着访问它无权访问的数据,预期结果是拒绝。
# Agents discover vulnerabilities faster than human patch cycles close them.
# That is Akamai's second headline finding. Treat "new CVE published" as an
# event with a deadline, and let the inventory drive who gets paged.
def patch_deadline(cve: dict) -> dict:
# Gateways, MCP servers and browser extensions that agents can reach
# get an SLA proportional to exploitability, not to convenience.
days = 3 if cve["actively_exploited"] else 7 if cve["cvss"] >= 9.0 else 30
owners = inventory.owners_of(cve["package"], kinds=("agent", "mcp", "extension"))
return {"cve": cve["id"], "dueInDays": days, "owners": owners}
def sweep(cves):
for cve in cves:
d = patch_deadline(cve)
if not d["owners"]:
# Unowned is worse than unpatched: nobody will ever patch it.
escalate("orphan dependency reachable by agents: " + cve["id"])
else:
notify(d["owners"], d)五、补丁周期追不上模型
报告的另一半是速度问题:模型发现漏洞比人类修补漏洞更快。示例 4 之外,示例 4 前面的第三个示例把这件事写成 SLA:正在被主动利用的漏洞 3 天、CVSS 9.0 以上 7 天、其余 30 天,并且把「谁能接触到这个依赖」作为派单依据——Agent、MCP 服务器、浏览器扩展都算在内。这里有一个容易被忽略的工程细节:没有归属方的依赖比未修补的依赖更危险,因为没有人会去修它,所以示例里对「孤儿依赖」直接升级处理。这其实与示例 1 的非人身份最小权限相呼应:当你无法确定一个 Agent 该有什么权限时,正确的默认值是没有权限。
// Behavioral governance means policy on what an agent does, not only on
// who it is. An agent that suddenly starts reading an unusual number of
// records is a signal even if its credentials are perfectly valid.
const behavioralPolicy = {
agentId: "support-agent",
baseline: { readsPerHour: 120, distinctCustomersPerHour: 40, exportsPerDay: 0 },
rules: [
{ when: "readsPerHour > 4 * baseline.readsPerHour", then: "step_up_auth" },
{ when: "distinctCustomersPerHour > 6 * baseline.distinctCustomersPerHour",
then: "throttle_and_notify" }, // classic bulk-export shape
{ when: "newEgressHost and !allowlisted", then: "block" },
],
evidence: ["traceId", "tool", "resourceIds", "promptHash"], // keep the why
};
// 61% of API attacks in 2025 involved unauthorized workflows and abnormal
// activity, up from 30% in 2024. Behaviour is where the attack now lives.超过 6% 的聊天对话包含敏感信息
六、给安全团队的落地顺序
第一,为每个 Agent 分配独立身份与最小权限作用域,绝不继承发起人的全会话权限(示例 1)。第二,把浏览器扩展与 MCP 服务器并入同一份资产清单,清点优先级按「AI 驱动」与「一年内权限变更」排序(示例 2)。第三,为对话通道定义敏感数据策略,个人账号路径默认拒绝(示例 3)。第四,把补丁 SLA 与可达性挂钩,把孤儿依赖升级处理(示例 4)。第五,建立行为基线,对偏离基线的 Agent 采取加强认证、限流或阻断(示例 5)。第六,定期做越权可达性回归,让「不可达」成为可被验证的断言而不是假设(示例 6)。Akamai 的 CSO Boaz Gelbord 把这轮变化概括为「一切、无处不在、同时发生」的三重威胁:内部 AI 使用、AI 进入客户产品、以及 AI 驱动的攻击。控制手段不必同样宏大,但必须同样具体。
📌 常见问题 FAQ
Akamai 这份报告的全名是什么?
报告名为《速度、规模与非人身份:Agent 威胁版图》(Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape),属于 Akamai 第 12 年的《互联网现状》(SOTI)安全报告系列。
「行为治理」和传统身份管理差在哪?
传统 IAM 假设主体稳定、权限低频变化;Agent 的能力随提示词与上下文变化,因此控制点需要从「你是谁」转向「你在做什么」,用行为基线来识别异常。
报告提到的浏览器风险有多具体?
超过 40% 的企业用户安装了 AI 驱动的浏览器扩展,其中 25% 在 12 个月内变更过权限。Akamai 将其称为关键且未受监控的攻击面。
聊天机器人泄漏数据的情况严重吗?
超过 6% 的聊天机器人对话包含敏感信息,主要为个人身份信息;相关报道指出其中相当一部分交互通过未受管的个人账号发生。
报告给 CISO 的核心建议是什么?
为非人身份建立独立的身份与最小权限、把浏览器扩展与 MCP 服务器纳入统一资产清单、为对话通道设定敏感数据策略、按可达性制定补丁 SLA,并对 Agent 行为建立基线与异常响应。
📚 参考资料
- Akamai — Akamai Report: Securing Agentic AI Requires Shift to Behavioral Governance (press release)
- Akamai Blog — Beyond Identity: Governing the Agentic Enterprise
- Akamai — Speed, Scale, and Nonhuman Identity: The Agentic Threat Landscape (SOTI report)
- Akamai — Apps, APIs, and DDoS 2026 security report (PDF)
- Technology Magazine — Akamai Report: Governing Non-Human Agentic AI Browser Risks (Sep 25, 2026)