高级检索

全球人工智能技术博弈下的软件供应链安全DeepSeek恶意软件包事件启示录

Software Supply Chain Security in the Global AI Technology Competition: Insights from the Deepseek Malicious Software Package Incident

  • 摘要: 随着人工智能(artificial intelligence, AI)技术的广泛应用,软件供应链面临着更为复杂多样的安全威胁。本文以2025年1月以来DeepSeek遭遇的网络攻击事件为切入点,深入剖析了软件供应链攻击手段和潜在风险,基于ATT&CK框架分析攻击背后涉及的战略、战术、技术和过程,以及大国博弈关系。为应对挑战,本文提出企业、行业和国家层面的全面治理策略。文章指出,软件供应链安全是AI时代国家安全的关键,需通过技术、管理和生态的立体化治理,筑牢AI发展基石,保障国家数字主权。

     

    Abstract: With the widespread application of artificial intelligence (AI) technology, the software supply chain is facing more complex and diverse security threats. This article takes the cyber-attack incidents that DeepSeek has encountered since January 2025 as the entry point and conducts an in-depth analysis of the attack methods and potential risks in the software supply chain. Based on the ATT&CK framework, the paper analyzes the strategies, tactics, techniques, procedures, and geopolitical competition behind the attacks. To address these challenges, the article proposes comprehensive governance strategies at the enterprise, industry, and national levels. The article emphasizes that software supply chain security is a key to national security in the AI era. It is essential to strengthen the foundation of AI development and safeguard national digital sovereignty through integrated governance that combines technology, management, and ecosystem approaches.

     

/

返回文章
返回