AWS Continuum: New Security Platform with AI Agents for Enterprises
Amazon Web Services
AWS has launched AWS Continuum, an integrated security platform with four AI agent-based capabilities covering the entire vulnerability management lifecycle: penetration testing, code review, threat modeling, and code vulnerability detection. The platform uses a tiered trust model and operates in four stages: discovery, prioritization, verification, and remediation. However, confusion arises as Security Agent, the predecessor product, still exists with the same features but under a different name.
AWS has launched AWS Continuum, an integrated security platform designed to automatically discover, execute, and fix security issues across codebases, dependencies, and applications. At launch, Continuum provides four agent-based capabilities: penetration testing, code review, threat modeling, and code vulnerability detection. The penetration testing and code review features allow teams to run penetration tests on demand or integrated into CI/CD workflows, and perform on-demand code reviews to identify vulnerabilities and verify compliance. Threat modeling analyzes application architecture to generate a system overview and a list of threats with severity, STRIDE classification, and actionable recommendations. Code vulnerability detection optimizes the discovery, prioritization, fixing, and monitoring of security flaws, analyzing both structured and unstructured data across the entire enterprise environment, including infrastructure, permissions, network topology, documents, internal communications, and business priorities. The service operates in four consecutive stages: discovery, prioritization, verification, and remediation. In the discovery stage, the entire enterprise backlog is evaluated and supplemented by scanning the environment, producing a comprehensive list of vulnerabilities and attack paths. In prioritization and verification, the service verifies whether affected components are deployed and accessible, and assesses potential business impact to filter critical vulnerabilities. AWS claims that building functional exploit examples in sandbox environments reduces false positives and provides solid evidence. In the remediation stage, the service proposes fixes such as network or policy adjustments or code patches, and can visualize the impact of changes and suggest rollback strategies. The service uses a tiered trust model, allowing security and product teams to choose the level of decision-making autonomy granted to the tool based on user-defined categories and risk profiles. Yan Cui, an AWS Serverless Hero, noted overlap between Continuum and existing AWS services, potentially causing confusion. Six months after Security Agent was launched, it was merged into another product line and renamed Continuum Penetration Testing and Continuum Code Scanning. However, Security Agent still has its own product page with the same features, and recent announcements include "Threat Modeling, Kiro features, and Claude Code plugin" for Security Agent. This creates uncertainty about which product to use. Competitors like Google AI Threat Defense and Microsoft MDASH offer similar capabilities, with Google pursuing cloud-platform-agnostic scanning and Microsoft integrating within its ecosystem. Penetration testing and code review are generally available with clear pricing, while threat modeling is in preview and code vulnerability detection is in limited preview.
- Сокращения
- CI/CD = Continuous Integration/Continuous Deployment
- STRIDE = Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege
Source: InfoQ 中国 —
original
