AI Security AI安全 3h ago Updated 1h ago 更新于 1小时前 46

1 in 5 Data Center Assets Are Within Easy Reach of Attackers 五分之一的数据中心资产处于攻击者轻松可达范围

Nearly 18% of data center cyber-physical systems (CPS) are "one hop" away from internet exposure, creating significant attack vectors. Only 0.4% of infrastructure assets are directly exposed to the internet, but proximity to exposed systems creates substantial risk. Building management systems show critical vulnerabilities: 88% use insecure protocols and 40% run outdated firmware. Power distribution units (41%) and HVAC systems (32%) are disproportionately vulnerable to one-hop attacks. Over 11, Claroty 研究发现全球大型数据中心中约18%的运营技术(OT)基础设施资产处于“一跳”可达的网络路径上,存在被攻击者利用的风险。 超过41%的电源分配单元和32%的暖通空调系统面临此类风险,表明关键物理控制系统的网络隔离不足。 大量设备存在已知漏洞且未修复,部分建筑管理系统使用不安全通信协议及过时固件,进一步加剧安全隐患。 报告建议采用零信任架构、持续暴露管理与协议感知威胁检测等措施提升数据中心的整体韧性。 随着AI数据中心建设速度加快,安全部署滞后问题日益凸显,亟需加强CPS(网络物理系统)防护策略。

70
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Nearly 18% of data center cyber-physical systems (CPS) are "one hop" away from internet exposure, creating significant attack vectors.
  • Only 0.4% of infrastructure assets are directly exposed to the internet, but proximity to exposed systems creates substantial risk.
  • Building management systems show critical vulnerabilities: 88% use insecure protocols and 40% run outdated firmware.
  • Power distribution units (41%) and HVAC systems (32%) are disproportionately vulnerable to one-hop attacks.
  • Over 11,000 OT control devices contain known exploited vulnerabilities (KEVs), posing serious operational risks.

Why It Matters

This research reveals a critical security gap in data center infrastructure where physical systems controlling cooling, power, and environmental functions remain dangerously accessible through network proximity rather than direct exposure. For AI practitioners and infrastructure operators, this highlights that securing AI data centers requires more than just protecting compute clusters—it demands comprehensive OT/IoT security strategies that address the interconnected nature of cyber-physical systems. The findings underscore the urgent need for zero-trust architectures and continuous monitoring as AI-driven workloads expand data center footprints.

Technical Details

  • Claroty analyzed over 750,000 data center assets including approximately 191,000 OT assets and 174,000 infrastructure components covering HVAC, power monitoring/distribution, fire management, and UPS systems.
  • The study identified that while only 1,000 infrastructure assets (0.4%) have direct internet exposure, roughly 32,000 assets (18%) reside within a single network hop from exposed systems, creating exploitable attack paths.
  • Vulnerability assessment revealed specific weaknesses: building management systems predominantly communicate via insecure protocols (88%), operate with outdated firmware (40%), and include thousands of devices affected by known exploited vulnerabilities in OT control systems like SCADA and PLCs.
  • Attack vectors include insecure communication protocols, unmanaged remote access technologies, flat network architectures, weak authentication mechanisms, and misconfigured asset communications that could enable disruption of cooling, power distribution, environmental controls, and backup generation systems.

Industry Insight

Data center operators must prioritize network segmentation and zero-trust architectures to isolate critical cyber-physical systems from potential attack pathways, recognizing that proximity to exposed systems creates equivalent risk to direct exposure. The high prevalence of insecure protocols and outdated firmware in building management systems indicates an urgent need for automated vulnerability management and protocol-aware threat detection solutions specifically designed for OT environments. As AI data centers continue expanding at unprecedented rates, integrating continuous exposure management into operational resilience frameworks will become essential to prevent cascading failures that could compromise both digital services and physical infrastructure stability.

TL;DR

  • Claroty 研究发现全球大型数据中心中约18%的运营技术(OT)基础设施资产处于“一跳”可达的网络路径上,存在被攻击者利用的风险。
  • 超过41%的电源分配单元和32%的暖通空调系统面临此类风险,表明关键物理控制系统的网络隔离不足。
  • 大量设备存在已知漏洞且未修复,部分建筑管理系统使用不安全通信协议及过时固件,进一步加剧安全隐患。
  • 报告建议采用零信任架构、持续暴露管理与协议感知威胁检测等措施提升数据中心的整体韧性。
  • 随着AI数据中心建设速度加快,安全部署滞后问题日益凸显,亟需加强CPS(网络物理系统)防护策略。

为什么值得看

本文揭示了当前数据中心在快速扩张过程中忽视网络安全尤其是OT/IoT领域潜在风险的严峻现实,对关注工业控制系统安全、云基础设施运维及AI算力底座保障的专业人士具有重要参考价值。它强调了传统IT边界思维向纵深防御转型的必要性,并为制定针对性缓解方案提供了实证依据。

技术解析

Claroty通过对超75万个数据中心资产进行扫描分析,识别出其中近19万项OT相关组件与约17.4万项基础设施单元(如UPS、消防、HVAC等),并量化其网络连接暴露程度。结果显示虽然仅有不到0.4%的设备直接连入公网,但高达18%可通过单跳访问间接触及——这意味着即使没有开放端口,只要相邻节点存在薄弱点即可构成攻击入口。此外,研究还指出特定类型设备普遍存在配置缺陷:例如88%的建筑管理系统依赖明文或未加密传输通道,40%运行着不再受支持的旧版固件版本;而在SCADA/PLC类核心控制器层面,则有超过一万台设备携带已被公开利用的安全漏洞。这些发现共同勾勒出一个典型场景: attackers 可能先入侵外围管理界面或第三方服务接口,再横向渗透至实际控制回路,最终导致冷却失效、断电甚至火灾响应失灵等严重后果。

行业启示

面对AI驱动的数据中心爆发式增长态势,企业必须重新评估现有安全治理框架是否足以支撑新型工作负载下的可靠性要求,尤其要将OT/CPS纳入统一风险管理视野而非孤立看待。同时应推动自动化合规检查工具落地实施,确保所有联网设备定期接受补丁更新与行为审计,并优先部署具备上下文感知的异常检测机制以捕捉隐蔽型威胁活动。长远来看,构建弹性 resilient architecture 将成为区分领先运营商与普通玩家的关键分水岭——只有那些能够平衡效率提升与风险控制双重目标的组织才能在未来竞争中占据主动地位。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全