
CrowdStrike เปิดตัว SafeMind ระบบปัญญาประดิษฐ์สำหรับงานความปลอดภัยไซเบอร์ที่นำโมเดลฝ่ายรุกและฝ่ายรับมาทำงานร่วมกันเป็นวงจรเดียว โดยพัฒนาบนโมเดลเปิด NVIDIA Nemotron และเตรียมให้ทำงานภายในแพลตฟอร์ม Falcon ของบริษัท ประกาศดังกล่าวมีขึ้นในงาน Fal.Con 2026 เมื่อวันที่ 1 กันยายน 2569
แนวคิดของ SafeMind คือให้ AI ฝ่ายรุกค้นหาเส้นทางที่ผู้โจมตีอาจใช้ ขณะที่ AI ฝ่ายรับประเมินและปิดช่องโหว่ แล้วนำผลจากทั้งสองด้านกลับมาเรียนรู้ร่วมกันอย่างต่อเนื่อง CrowdStrike ระบุว่าระบบถูกออกแบบเฉพาะสำหรับทีมรักษาความปลอดภัย ไม่ใช่โมเดลอเนกประสงค์ที่นำมาปรับใช้ภายหลัง
สองโมเดลทำหน้าที่ต่างกัน
SafeMind เปิดตัวพร้อมโมเดลหลักสองส่วน ได้แก่ Red Tempest สำหรับจำลองสถานการณ์โจมตีขั้นสูงและพฤติกรรมของฝ่ายตรงข้ามที่ใช้ AI และ Blue Solano สำหรับป้องกันทรัพย์สินขององค์กรด้วยแนวทางที่อิงจากการปฏิบัติงานจริง โมเดลทั้งคู่เชื่อมผ่านชุดควบคุมหรือ harnesses เพื่อแลกเปลี่ยนผลลัพธ์ในวงจรปิด
บริษัทระบุว่าข้อมูลฝึกครอบคลุมข้อมูลตรวจจับจากเซ็นเซอร์ Falcon ข่าวกรองภัยคุกคาม บันทึกเหตุการณ์จากบริการ Falcon Complete MDR และประสบการณ์ตอบสนองเหตุการณ์ย้อนหลัง 15 ปี ส่วนโครงสร้างพื้นฐานการฝึกและการประมวลผลใช้บริการ AI Cloud ของ CoreWeave ร่วมด้วย
ตัวเลขประสิทธิภาพยังเป็นผลประเมินจากบริษัท
ตามผลประเมินที่ CrowdStrike เปิดเผย SafeMind มีอัตราตรวจจับสูงกว่ากลุ่มโมเดลอ้างอิง 29% แก้ไขเหตุการณ์แบบครบกระบวนการเร็วขึ้น 6 เท่า และลดต้นทุนการตรวจจับกับการแก้ไขได้ 99% อย่างไรก็ตาม ตัวเลขเหล่านี้เป็นผลที่บริษัทผู้พัฒนารายงาน จึงควรรอรายละเอียดวิธีทดสอบ การตรวจสอบโดยหน่วยงานภายนอก และผลการใช้งานจริงในสภาพแวดล้อมที่หลากหลาย
ความร่วมมือระหว่าง CrowdStrike และ NVIDIA สะท้อนทิศทางใหม่ของตลาดไซเบอร์ซีเคียวริตี้ ซึ่งกำลังเปลี่ยนจาก AI ที่ช่วยสรุปหรือแจ้งเตือน ไปสู่ระบบ agentic AI ที่วางแผนและดำเนินการบางส่วนได้เอง องค์กรที่นำระบบประเภทนี้มาใช้ยังจำเป็นต้องกำหนดสิทธิ์ ควบคุมข้อมูล ตรวจสอบผลลัพธ์ และคงมนุษย์ไว้ในขั้นตอนตัดสินใจที่มีความเสี่ยงสูง
English Version
CrowdStrike Pairs Offensive and Defensive AI in New SafeMind Security System
CrowdStrike has introduced SafeMind, a purpose-built agentic cybersecurity system that combines offensive and defensive AI models in a continuous loop. Built with NVIDIA Nemotron open models, the system is designed to operate natively within the CrowdStrike Falcon platform.
SafeMind launches with two specialized models. Red Tempest simulates advanced attack paths and AI-enabled adversaries, while Blue Solano focuses on defensive measures for protecting enterprise assets. Harnesses connect the two models so that findings from one side can inform the other.
CrowdStrike says the models use Falcon sensor telemetry, threat intelligence, managed detection and response annotations, and lessons from 15 years of incident response work. CoreWeave provides AI cloud infrastructure for training and inference.
Company evaluations claim a 29% higher detection rate, six-times faster end-to-end remediation and a 99% reduction in detection and remediation costs compared with selected frontier-model and open-source baselines. These figures are vendor-reported and will require independent validation and real-world testing across different environments.
The announcement illustrates a broader shift from AI that merely summarizes alerts toward systems capable of planning and taking security actions. Strong access controls, data governance, auditability and human oversight will remain essential when deploying autonomous security tools.
แหล่งข้อมูลและเครดิตภาพ / Sources & Image Credit
- CrowdStrike Investor Relations: SafeMind announcement
- CrowdStrike: Earlier NVIDIA collaboration details
- NVIDIA NGC Catalog: Nemotron resources
- CRN: Independent coverage of the collaboration
เจ้าของภาพ: CrowdStrike Holdings, Inc. | ลิงก์ต้นทางภาพ
#CrowdStrike #SafeMind #NVIDIA #Cybersecurity #AI #ความปลอดภัยไซเบอร์ #เทคโนโลยี
Leave a comment