书面答复 · 2026-09-08 · 届国会 15

ASPIRE 2A 与科技研究局 Exanet 网络安全事件:调查报告是否公开及所采取的数据恢复措施

ASPIRE 2A 与科技研究局 Exanet 网络安全事件:调查报告是否公开及所采取的数据恢复措施

工人党议员严燕松(Mr Gerald Giam Yean Song)书面询问贸工部长(能源与工业):新加坡国家超级计算中心(NSCC)ASPIRE 2A 与科技研究局(A*STAR)Exanet 网络近期的网络安全事件,完整调查报告是否公开;采取了哪些恢复、验证和加固措施;是否有数据外泄。陈诗龙博士(Dr Tan See Leng)书面答复:两起事件(2026 年 5 月 22 日、7 月 24 日)发生后,受影响系统被迅速隔离调查,外部鉴证专家查明根本原因,未发现数据受损或外泄证据;报告不会公开,以免为恶意行为者提供有用信息。系统经重建、扫描和检查后才恢复使用,并收紧访问控制、加强终端防护;NSCC 与 A*STAR 已加快红队演练等既有计划,经验已推广至整个科研基础设施。

为什么重要

国家超算 ASPIRE 2A 与科技研究局 Exanet 两起事件未发现数据外泄证据,但调查报告不会公开

关键要点

  • • NSCC 的 ASPIRE 2A 系统(2026 年 5 月 22 日)与 A*STAR 的 Exanet 网络(2026 年 7 月 24 日)发生事件后,受影响系统被迅速隔离并立即展开调查。
  • • 外部鉴证专家受聘查明每起事件的根本原因;详细调查未发现两起事件有数据受损或外泄的证据。
  • • 详细调查报告不会公开,理由是可能为恶意行为者提供有用信息。
  • • 受影响系统和设备经重建、扫描攻击残留、检查并获准后才恢复服务,同时立即收紧访问控制的执行并加强终端防护。
  • • NSCC 与 A*STAR 加快事件前已启动的网络安全计划,包括通过更复杂的红队演练加强威胁模拟,经验教训已应用于整个科研基础设施。
政府立场

政府表示两起事件均已处置,未发现数据受损或外泄,并已加强安全措施、加快既有网络安全计划。政府拒绝公开详细调查报告,理由是这可能为恶意行为者提供有用信息。

质询立场

提问议员严燕松(工人党)要求公开完整调查报告,并追问具体的恢复、验证和加固措施以及是否有数据外泄、哪些数据受损。

政策信号

国家超算与科研网络已被当作需重点防护的 AI 算力基础设施;政府在事件披露上采取结论公开、细节保密的做法,议会对透明度的要求与安全考量之间的张力可能持续。

“详细调查未发现两起事件中有任何数据受损或外泄的证据。”

参与人员 (2)

完整译文(中文)

Hansard 原始记录 · 2026-09-26

53 号,严燕松先生询问贸工部长(能源与工业):(a) 近期影响新加坡国家超级计算中心 ASPIRE 2A 系统和科技研究局 Exanet 网络的网络安全事件,完整调查报告是否会公开发布;(b) 采取了哪些具体的恢复、验证和加固措施;以及 (c) 是否有任何数据被外泄,如果有,哪些数据受到损害。

陈诗龙博士:2026 年 5 月 22 日新加坡国家超级计算中心(NSCC)ASPIRE 2A 系统及 2026 年 7 月 24 日科技研究局(A*STAR)Exanet 网络发生网络安全事件后,受影响的系统被迅速隔离,并立即展开调查,以确定事件的性质、范围和影响。

当局也聘请了外部鉴证专家调查并确定每起事件的根本原因。详细调查未发现两起事件中有任何数据受损或外泄的证据。详细调查报告不会公开发布,因为这样做可能为恶意行为者提供有用的信息。

受影响的 ASPIRE 2A 系统和 Exanet 网络中的计算设备都已重建、扫描是否有任何攻击残留、经过检查并获准使用后才恢复服务。当局也立即实施了额外的安全措施,包括更严格地执行访问控制和加强终端防护,以强化防范未经授权访问的保障。

NSCC 和 A*STAR 定期检讨其网络安全规程,确保这些规程保持稳健和与时俱进,并已加快推进事件发生前就已启动的网络安全计划,例如通过更复杂的红队演练加强网络安全威胁模拟。从这些事件中汲取的教训也已应用于我们的整个科研基础设施。

英文原文

SPRS Hansard 原始记录 · 抓取日期:2026-09-26

53 Mr Gerald Giam Yean Song asked the Minister for Trade and Industry (Energy and Industry) (a) whether full investigation reports on the recent cybersecurity incidents affecting National Supercomputing Centre Singapore's ASPIRE 2A and A*STAR's Exanet network will be publicly released; (b) what specific recovery, validation and hardening measures were taken; and (c) whether any data was exfiltrated and, if so, what data was compromised.

Dr Tan See Leng : Following the cybersecurity incidents affecting the National Supercomputing Centre Singapore's (NSCC's) ASPIRE 2A system on 22 May 2026 and Agency for Science, Technology and Research's (A*STAR's) Exanet network on 24 July 2026, the affected systems were promptly isolated, and investigations were immediately conducted to establish the nature, extent and impact of the incidents.

External forensic specialists were also engaged to investigate and establish the root cause in each case. Detailed investigations found no evidence of data compromise or exfiltration in either incident. The detailed investigation reports will not be publicly released, as doing so could provide information useful to malicious actors.

The affected ASPIRE 2A system and computing devices in the Exanet network were rebuilt, scanned for any residual elements of the attack, inspected and cleared for use before being returned to service. Additional security measures, including tighter enforcement of access controls and enhancement of endpoint protection, were immediately implemented to strengthen safeguards against unauthorised access.

NSCC and A*STAR conduct regular reviews of their cybersecurity protocols to ensure these remain robust and current and have accelerated their cybersecurity initiatives which had commenced prior to the incidents, such as enhancing cybersecurity threat simulation through more sophisticated red teaming. Lessons learnt from these incidents have also been applied across our research infrastructure.

引用此条

新加坡 AI 观察. ASPIRE 2A 与科技研究局 Exanet 网络安全事件:调查报告是否公开及所采取的数据恢复措施. 检索日期 2026-09-26, https://sgai.md/zh/debates/written-answer-24497/

同主题更多