统一管理人机身份,降低47%安全事件发生率
The Human-Machine Identity Blur: A Unified Framework for Cybersecurity Risk Management in 2025
- 将人机身份视为连续体,打破传统隔离管理
- 采用统一框架后,安全事件减少47%,响应速度提升62%
- 适合面临身份泛滥的大型企业与安全团队参考
现代企业正面临数字身份前所未有的激增,机器身份已显著超过人类身份。本文研究了“人机身份模糊”带来的新型网络安全风险——即人与机器身份在授权交叠、权限委托中形成的新攻击面。基于行业数据、专家意见和真实事件分析,发现现有身份管理模型将人与机器分隔处理存在治理漏洞。为此提出统一身份治理框架,包含四大原则:将身份视为连续体而非二元对立;对所有身份类型应用一致的风险评估;基于零信任实施持续验证;贯穿全生命周期的治理。研究显示,采用该框架的组织可降低47%的身份相关安全事件,事件响应时间提升62%。文章最后提供可落地的实施路径,并指出未来在自主AI系统日益普及背景下的研究方向。
原文摘要 · Abstract (English)
The modern enterprise is facing an unprecedented surge in digital identities, with machine identities now significantly outnumbering human identities. This paper examines the cybersecurity risks emerging from what we define as the "human-machine identity blur" - the point at which human and machine identities intersect, delegate authority, and create new attack surfaces. Drawing from industry data, expert insights, and real-world incident analysis, we identify key governance gaps in current identity management models that treat human and machine entities as separate domains. To address these challenges, we propose a Unified Identity Governance Framework based on four core principles: treating identity as a continuum rather than a binary distinction, applying consistent risk evaluation across all identity types, implementing continuous verification guided by zero trust principles, and maintaining governance throughout the entire identity lifecycle. Our research shows that organizations adopting this unified approach experience a 47 percent reduction in identity-related security incidents and a 62 percent improvement in incident response time. We conclude by offering a practical implementation roadmap and outlining future research directions as AI-driven systems become increasingly autonomous.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。