Source: H3C |Original Link


On July 16, the 3rd Yuewang'an Cybersecurity New Technology Exchange Conference was convened in Guangzhou. The conference brought together academicians, hundreds of experts and scholars, industry leaders, and corporate representatives from the cybersecurity sector to conduct in-depth discussions on the new challenges and opportunities in cybersecurity in the AI era, and to explore new directions for industrial development. H3C Group was invited to attend this prestigious event. Guo Tianqi, Chief Engineer of H3C Information Security Technology Co., Ltd., delivered a keynote speech, addressing emerging security imperatives in the digital intelligence era through forward-looking strategic planning and technical practices in AI security.

Currently, generative AI and agent technologies are rapidly permeating various industries, becoming core drivers for enhancing enterprise productivity and empowering digital transformation. However, during the large-scale commercialization of business agents, the absence of systematic security safeguards may give rise to multiple novel security risks. Concurrently, attack surfaces across computing infrastructure, model security, and application security continue to expand. The pace of cyber offense and defense is shifting from human response speed to machine computation speed, rendering traditional defense systems inadequate for the evolving security landscape.

"Leveraging AI to drive security is an imperative choice for rebalancing offense and defense in the digital era and establishing a proactive intelligent defense system," stated Guo Tianqi during his speech. Centered on the philosophy of "Active Security," H3C focuses on three strategic pillars: "AI in SEC, AI for SEC, and SEC for AI." By natively embedding security capabilities into the full-link infrastructure spanning cloud, network, computing, storage, and endpoints, and by deeply integrating multi-dimensional security data across traffic, identity, applications, computing power, and behavior, H3C has established an endogenous intelligent security protection system characterized by unified planning, construction, and operation. This system comprehensively covers cutting-edge application scenarios such as large models, AI agents, and computing clusters, systematically addressing new security risks arising from the evolution of AI technology.

AI in SEC: Embedding AI in Security Devices to Identify and Protect AI

In response to diversified business scenarios and emerging protection requirements in the AI era, H3C is accelerating the intelligent upgrade of its entire security product line to build a full-stack AI security capability system. Notably, the industry's highest-performance AI firewall, designed specifically for AI computing scenarios, redefines next-generation perimeter security benchmarks through superior hardware performance and deep AI integration.

In terms of performance, the H3C AI firewall adopts a distributed architecture equipped with dedicated hardware acceleration engines, delivering up to 16 Tbps throughput with latency below 1 microsecond. It fully meets the ultra-high traffic and low-latency protection requirements of large-scale data centers and AI computing clusters. Furthermore, it supports fingerprint recognition for over 10,000 AI applications, enabling granular identification and control of AI business traffic.

On the software front, the product incorporates H3C's proprietary AI security engine, integrating both traditional machine learning and deep learning architectures. Its intelligent semantic analysis technology achieves a 98% accuracy rate in identifying prompt injection intents. Additionally, leveraging spatiotemporal feature joint modeling and a CNN-LSTM combined engine, it attains a 95% threat detection rate while maintaining a false positive rate of 0.15%. This effectively addresses the industry-wide challenge of precise encrypted traffic detection, marking a capability leap from traditional traffic-level protection to instruction-level granular defense.

AI for SEC: Embracing Security Agents to Reshape Security Operations Paradigms

Traditional security operations rely heavily on manual intervention, resulting in three critical cascading dilemmas: overwhelming volumes of redundant alerts and high false positive rates trap security personnel in ineffective investigations, leading to slow threat assessment and severely delayed remediation; disparate security devices operate in silos with disconnected data and uncoordinated policies, failing to form a cohesive defense and leaving blind spots; and manual updates to security rules cannot keep pace with the rapid iteration of AI-driven threats, causing rigid defense systems. The newly launched Agentic SOC platform, featuring core capabilities in autonomous decision-making, collaboration, and evolution, serves as the "intelligent brain" of H3C's AI security system, directly addressing these pain points in traditional security operations.

Regarding autonomous decision-making, leveraging AI large models achieves a 95% alert noise reduction rate and automatically generates remediation plans, reducing MTTR (Mean Time to Respond) by 90%. In terms of autonomous collaboration, the platform integrates over 30 security agents to orchestrate autonomous responses across multiple security devices, establishing a globally coordinated defense system. For autonomous evolution, it captures expert knowledge online, supports custom agent extensions, and continuously iterates security large models based on live network data, ensuring that protection capabilities evolve in sync with business operations.

SEC for AI: Establishing Full-Stack Protection Across Computing Power, Models, and Agents

As AI increasingly participates in business decision-making and automated execution, security frameworks are evolving from traditional perimeter defense to application-centric protection represented by agents. H3C has established a full-stack protection system covering computing power, models, and agents, achieving precise risk matching at each layer and coordinated prevention across the entire chain.

In terms of computing power security, a trusted and secure environment is comprehensively established through network protection to defend against attacks and prevent unauthorized use of computing resources; container security to enable real-time monitoring and prevent container escapes; and endpoint security to identify environmental vulnerabilities and block uncontrolled actions. Regarding model security, H3C provides a dual-engine solution comprising model evaluation and Lingxi Guardian to ensure training data remains uncompromised by poisoning attacks and that output content is compliant and controllable. In the domain of application security, an AI Security Gateway serves as the core component, integrating agent identity governance, dynamic authorization, content security, and data security protection to construct an agent defense system centered on identity and permissions.

AI Security Gateway: Integrated Protection for an Intelligent Agent Security Control Hub

Designed specifically for intelligent agent security, the H3C AI Security Gateway integrates four core capabilities: identity security, runtime security, data security, and content security. Focusing on end-to-end protection throughout agent interactions, it serves as a central hub for permission management and risk control in the AI era.

Leveraging streaming graph technology, the product constructs an identity and permission relationship network for intelligent agents, enabling real-time perception of permission changes, discovery of hidden associations, and identification of potential privilege escalation. It features an industry-first three-tier dynamic permission engine that utilizes semantic recognition to precisely detect anomalous behaviors deviating from task objectives, combined with intelligent anomaly detection models to ensure behavioral logic compliance. Furthermore, a full-link audit engine synchronously records agent reasoning logic and complete behavioral traces, ensuring traceability and accountability.

At the content and data security level, the system supports deep inspection of all AI interaction content to accurately intercept malicious instructions and strictly prevent sensitive data leakage, thereby safeguarding enterprise data assets. At the runtime security level, it supports multi-dimensional token quota and traffic management based on applications, APIs, and users, effectively preventing computing resource exhaustion and abuse while ensuring cost controllability and budget transparency. Additionally, the product natively supports integration with over 20 mainstream large models and can intelligently schedule optimal service nodes based on real-time load, request type, response latency, GPU utilization, and cost budgets. It is also fully compatible with standard agent protocols such as MCP.