← 목록으로

AI가 만드는 보안의 역설…인섹시큐리티, ‘파일부터 의심하라’는 제로 트러스트 전략 제시

AI가 만드는 보안의 역설…인섹시큐리티, ‘파일부터 의심하라’는 제로 트러스트 전략 제시

요약

인섹시큐리티가 옵스왓과 함께 개최한 ‘제로 트러스트 파일 보안 세미나’에서 AI 시대 파일 기반 사이버 공격 대응 전략을 소개했다. 행사에서는 ‘Trust No File, Trust No Device’를 핵심 원칙으로 한 예방 중심 보안 체계와 멀티 안티바이러스, CD... The post AI가 만드는 보안의 역설…인섹시큐리티, ‘파일부터 의심하라’는 제로 트러스트 전략 제시 appeared first on 벤처스퀘어.

본문

  • 인섹시큐리티·옵스왓, 제로 트러스트 파일 보안 세미나 개최
  • AI 기반 공격 대응 위한 ‘Trust No File, Trust No Device’ 전략 강조

디지털 포렌식 및 악성코드 분석 전문기업 인섹시큐리티(대표 김종광)가 글로벌 사이버 보안 기업 옵스왓(OPSWAT)과 함께 개최한 ‘제로 트러스트 기반 파일 보안 세미나’를 성황리에 마쳤다고 24일 밝혔다.

이번 세미나는 지난 23일 서울 독산동 인섹시큐리티 교육센터에서 진행됐으며, 기업 및 공공기관 정보보호 책임자(CISO), 보안 관리자, 보안관제센터(SOC) 운영자 등 보안 실무자들이 참석한 가운데 최신 파일 보안 전략과 실제 구축 사례를 공유하는 자리로 마련됐다.

최근 생성형 AI 확산과 함께 랜섬웨어, 공급망 공격, 이메일 기반 악성코드, 이동식 저장매체를 활용한 공격이 빠르게 증가하는 가운데 기존 탐지 중심 보안 체계만으로는 대응이 어려워지고 있다는 점이 주요 화두로 다뤄졌다.

인섹시큐리티, 제로 트러스트 전략 제시 (사진 제공: 인섹시큐리티)

AI 시대, ‘탐지’보다 ‘예방’이 중요해진다

인섹시큐리티는 이날 세미나에서 AI 기술 발전으로 공격자들의 악성코드 제작과 피싱 공격이 더욱 자동화·고도화되고 있다고 설명했다. 특히 취약점이 공개된 이후 실제 공격이 이뤄지기까지 걸리는 시간이 급격히 짧아지면서 보안 전략 역시 사후 탐지에서 사전 예방 중심으로 전환되고 있다고 강조했다. 이에 따라 기업들은 이미 알려진 위협뿐 아니라 아직 식별되지 않은 제로데이 공격까지 고려한 보안 체계를 구축해야 하며, 내부로 유입되기 전 단계에서 공격을 차단하는 전략이 중요해지고 있다는 설명이다.

세미나에서는 미국 국립표준기술연구소(NIST)의 제로 트러스트 아키텍처(NIST SP 800-207)와 미국 사이버보안 및 인프라보안국(CISA)의 제로 트러스트 성숙도 모델을 기반으로 한 최신 보안 전략도 소개됐다.

특히 이메일 첨부파일과 웹 다운로드, 파일 공유 시스템, USB 저장장치 등 모든 파일 유입 경로를 기본적으로 신뢰하지 않는 ‘Trust No File’과 단말 자체를 신뢰하지 않는 ‘Trust No Device’ 개념이 핵심 원칙으로 제시됐다.

파일 자체를 검증하는 보안 패러다임

이날 행사에서는 옵스왓의 통합 파일 보안 플랫폼 ‘메타디펜더(MetaDefender)’를 중심으로 실제 구축 사례와 기술 시연도 진행됐다.

메타디펜더는 파일 유입 단계부터 검증과 무해화, 분석, 통제를 수행하는 예방 중심의 제로 트러스트 파일 보안 플랫폼이다. 멀티 안티바이러스 기반 악성코드 검사와 콘텐츠 무해화 및 재구성(CDR), AI 기반 샌드박스 분석, 파일 기반 취약점 분석(FBVA), 데이터 유출 방지(DLP), 이동식 저장매체 보안 기능 등을 통합 제공한다.

특히 이메일과 웹 다운로드, USB 저장매체 등 다양한 경로를 통해 유입되는 파일에 대해 다계층 보안 검증을 수행함으로써 알려진 악성코드뿐 아니라 미확인 위협과 제로데이 공격까지 사전에 식별하고 차단할 수 있도록 지원한다.

인섹시큐리티는 제조와 에너지, 국방, 공공기관 등 중요 기반시설을 중심으로 파일 기반 공격이 증가하는 상황에서 예방 중심의 파일 보안 체계 구축이 앞으로 더욱 중요해질 것으로 전망했다.

Like this:

Like Loading...

The Security Paradox Created by AI… InsecSecurity Presents Zero Trust Strategy: 'Suspect the Files First'

Insec Security (CEO Jong-kwang Kim), a company specializing in digital forensics and malware analysis, announced on the 24th that it successfully concluded the 'Zero Trust-based File Security Seminar' co-hosted with global cybersecurity company OPSWAT.

This seminar was held on the 23rd at the Insec Security Training Center in Doksan-dong, Seoul, and was organized to share the latest file security strategies and actual implementation cases with the attendance of security practitioners, including Chief Information Security Officers (CISOs), security managers, and Security Operations Center (SOC) operators from companies and public institutions.

With the recent proliferation of generative AI, ransomware, supply chain attacks, email-based malware, and attacks utilizing removable storage media are rapidly increasing; the fact that it is becoming difficult to respond with existing detection-centric security systems alone was discussed as a major topic.

Insec Security Presents Zero Trust Strategy (Photo courtesy of Insec Security)

In the AI era, 'prevention' becomes more important than 'detection'

At the seminar, Insec Security explained that advancements in AI technology are making malware creation and phishing attacks more automated and sophisticated. In particular, they emphasized that as the time between vulnerability disclosure and actual attack execution shortens dramatically, security strategies are shifting from reactive detection to proactive prevention. Accordingly, companies must establish security systems that account for not only known threats but also unidentified zero-day attacks, and strategies to block attacks before they enter the system are becoming increasingly important.

The seminar also introduced the latest security strategies based on the National Institute of Standards and Technology (NIST) Zero Trust Architecture (NIST SP 800-207) and the Cybersecurity and Infrastructure Security Agency (CISA) Zero Trust Maturity Model.

In particular, the concepts of 'Trust No File,' which fundamentally distrusts all file entry sources such as email attachments, web downloads, file sharing systems, and USB storage devices, and 'Trust No Device,' which distrusts the device itself, were presented as core principles.

Security paradigm that verifies the file itself

At the event, actual implementation cases and technical demonstrations were also conducted, centering on Opswat's integrated file security platform, MetaDefender.

MetaDefender is a prevention-oriented, zero-trust file security platform that performs verification, neutralization, analysis, and control from the moment a file enters the system. It integrates multi-antivirus-based malware scanning, Content Disarm and Reconstruction (CDR), AI-based sandbox analysis, File-Based Vulnerability Analysis (FBVA), Data Loss Prevention (DLP), and removable storage security features.

In particular, by performing multi-layered security verification on files entering through various channels such as email, web downloads, and USB storage media, it supports the proactive identification and blocking of not only known malware but also unidentified threats and zero-day attacks.

Insec Security predicted that establishing a prevention-oriented file security system will become increasingly important in the future, given the rising number of file-based attacks centered on critical infrastructure in manufacturing, energy, defense, and public institutions.

AIが作るセキュリティのパラドックス…インセクシーキュリティ、「ファイルから疑う」というゼロ信頼戦略を提示

デジタルフォレンジックおよび悪性コード分析専門企業のインセキュリティ(代表キム・ジョングァン)がグローバルサイバーセキュリティ企業オプスワット(OPSWAT)と共に開催した「ゼロトラストベースのファイルセキュリティセミナー」を盛況裏に終えたと24日明らかにした。

今回のセミナーは去る23日ソウル毒山洞インセクシーキュリティ教育センターで行われ、企業及び公共機関情報保護責任者(CISO)、セキュリティ管理者、セキュリティ管理センター(SOC)運営者などセキュリティ実務者らが参加した中で最新のファイルセキュリティ戦略と実際構築事例を共有する場として設けられた。

最近生成型AIの拡散とともに、ランサムウェア、サプライチェーン攻撃、電子メールベースのマルウェア、リムーバブルストレージ媒体を活用した攻撃が急速に増加する中、既存の検出中心セキュリティ体系だけでは対応が難しくなっているという点が主な話題になった。

インセクシーキュリティ、ゼロトラスト戦略提示(写真提供:インセクシーキュリティ)

AI時代、「検出」より「予防」が重要になる

インセクシーキュリティはこの日セミナーでAI技術の発展で攻撃者のマルウェア製作とフィッシング攻撃がさらに自動化・高度化していると説明した。特に脆弱性が公開されて以来、実際の攻撃が行われるまでにかかる時間が急激に短くなり、セキュリティ戦略も事後検知から事前予防中心に転換されていると強調した。これにより、企業は既に知られている脅威だけでなく、まだ識別されていないゼロデイ攻撃まで考慮したセキュリティ体系を構築しなければならず、内部に流入する前の段階で攻撃を遮断する戦略が重要になっているという説明だ。

セミナーでは、米国国立標準技術研究所(NIST)のゼロトラストアーキテクチャ(NIST SP 800-207)と、米国サイバーセキュリティおよびインフラセキュリティ局(CISA)のゼロトラスト成熟度モデルを基盤とした最新のセキュリティ戦略も紹介された。

特に電子メールの添付ファイルとWebダウンロード、ファイル共有システム、USBストレージなど、すべてのファイル流入経路を基本的に信頼しない「Trust No File」と端末自体を信頼しない「Trust No Device」の概念が核心原則として提示された。

ファイル自体を検証するセキュリティパラダイム

この日のイベントでは、オプスワットの統合ファイルセキュリティプラットフォーム「メタディフェンダー(MetaDefender)」を中心に、実際の構築事例と技術デモも行われた。

メタディフェンダーは、ファイル侵入段階から検証、無害化、分析、制御を実行する予防中心のゼロ信頼ファイルセキュリティプラットフォームです。マルチアンチウイルスベースのマルウェアスキャンとコンテンツの無害化と再構成(CDR)、AIベースのサンドボックス分析、ファイルベースの脆弱性分析(FBVA)、データ漏洩防止(DLP)、リムーバブルストレージメディアセキュリティ機能などを統合提供します。

特に電子メールやWebダウンロード、USBストレージメディアなど多様なパスを通じて流入するファイルに対して多階層セキュリティ検証を行うことで知られているマルウェアだけでなく、未確認の脅威やゼロデイ攻撃まで事前に識別してブロックすることができるように支援する。

インセクシーキュリティは、製造とエネルギー、国防、公共機関など重要基盤施設を中心にファイルベース攻撃が増加する状況で、予防中心のファイルセキュリティ体系構築が今後さらに重要になると見込んだ。

人工智能带来的安全悖论……InsecSecurity推出零信任策略:“首先怀疑文件”

专注于数字取证和恶意软件分析的 Insec Security(CEO 金钟光)于 24 日宣布,与全球网络安全公司 OPSWAT 联合举办的“基于零信任的文件安全研讨会”已成功举办。

本次研讨会于 23 日在首尔独山洞的 Insec 安全培训中心举行,旨在与来自公司和公共机构的首席信息安全官 (CISO)、安全经理和安全运营中心 (SOC) 操作员等安全从业人员分享最新的文件安全策略和实际实施案例。

随着生成式人工智能的迅速普及,勒索软件、供应链攻击、基于电子邮件的恶意软件以及利用可移动存储介质的攻击正在迅速增加;仅靠现有的以检测为中心的安全系统难以应对这一事实,成为了一个重要的讨论话题。

Insec Security推出零信任策略(图片由Insec Security提供)

在人工智能时代,“预防”比“检测”更重要。

在研讨会上,Insec Security解释说,人工智能技术的进步使得恶意软件的创建和网络钓鱼攻击更加自动化和复杂。他们特别强调,随着漏洞披露到实际攻击执行之间的时间大幅缩短,安全策略正从被动检测转向主动预防。因此,企业必须建立能够应对已知威胁和未知零日攻击的安全系统,并且在攻击进入系统之前就将其拦截的策略变得越来越重要。

研讨会还介绍了基于美国国家标准与技术研究院 (NIST) 零信任架构 (NIST SP 800-207) 和网络安全与基础设施安全局 (CISA) 零信任成熟度模型的最新安全策略。

具体而言,书中提出了“不信任任何文件”和“不信任任何设备”的概念,前者从根本上不信任所有文件输入来源,如电子邮件附件、网络下载、文件共享系统和 USB 存储设备;后者则不信任设备本身。这两个概念被视为核心原则。

验证文件本身的安全范式

活动期间,还进行了实际应用案例和技术演示,重点是 Opswat 的集成文件安全平台 MetaDefender。

MetaDefender 是一个以预防为导向的零信任文件安全平台,从文件进入系统的那一刻起,就执行验证、中和、分析和控制。它集成了基于多种杀毒软件的恶意软件扫描、内容解除和重建 (CDR)、基于人工智能的沙箱分析、基于文件的漏洞分析 (FBVA)、数据丢失防护 (DLP) 以及可移动存储安全功能。

具体来说,它通过对通过电子邮件、网络下载和 USB 存储介质等各种渠道进入的文件执行多层安全验证,支持主动识别和阻止已知的恶意软件以及未知的威胁和零日攻击。

Insec Security 预测,鉴于针对制造业、能源、国防和公共机构等关键基础设施的文件攻击数量不断增加,建立以预防为导向的文件安全系统在未来将变得越来越重要。

Le paradoxe de la sécurité créé par l'IA… InsecSecurity présente une stratégie de confiance zéro : « Méfiez-vous d'abord des fichiers »

Insec Security (PDG Jong-kwang Kim), une société spécialisée dans l'analyse forensique numérique et l'analyse des logiciels malveillants, a annoncé le 24 avoir conclu avec succès le « Séminaire sur la sécurité des fichiers basé sur le principe de confiance zéro » co-organisé avec la société mondiale de cybersécurité OPSWAT.

Ce séminaire s'est tenu le 23 au centre de formation Insec Security à Doksan-dong, Séoul, et a été organisé pour partager les dernières stratégies de sécurité des fichiers et des cas de mise en œuvre réels avec la participation de praticiens de la sécurité, notamment des responsables de la sécurité des systèmes d'information (RSSI), des gestionnaires de sécurité et des opérateurs de centres d'opérations de sécurité (SOC) d'entreprises et d'institutions publiques.

Avec la prolifération récente de l'IA générative, les ransomwares, les attaques contre la chaîne d'approvisionnement, les logiciels malveillants véhiculés par e-mail et les attaques utilisant des supports de stockage amovibles augmentent rapidement ; le fait qu'il devienne difficile de répondre uniquement avec les systèmes de sécurité existants axés sur la détection a été abordé comme un sujet majeur.

Insec Security présente sa stratégie Zero Trust (Photo fournie par Insec Security)

À l'ère de l'IA, la « prévention » devient plus importante que la « détection ».

Lors du séminaire, Insec Security a expliqué que les progrès de l'intelligence artificielle rendent la création de logiciels malveillants et les attaques de phishing plus automatisées et sophistiquées. L'entreprise a notamment souligné que, face à la réduction drastique du délai entre la divulgation d'une vulnérabilité et l'exécution effective d'une attaque, les stratégies de sécurité évoluent d'une détection réactive vers une prévention proactive. Par conséquent, les entreprises doivent mettre en place des systèmes de sécurité prenant en compte non seulement les menaces connues, mais aussi les attaques zero-day non identifiées. Les stratégies de blocage des attaques avant leur intrusion dans le système revêtent une importance croissante.

Le séminaire a également présenté les dernières stratégies de sécurité basées sur l'architecture Zero Trust du National Institute of Standards and Technology (NIST) (NIST SP 800-207) et le modèle de maturité Zero Trust de la Cybersecurity and Infrastructure Security Agency (CISA).

En particulier, les concepts de « Ne faites confiance à aucun fichier », qui consiste fondamentalement à se méfier de toutes les sources d'entrée de fichiers telles que les pièces jointes aux courriels, les téléchargements Web, les systèmes de partage de fichiers et les périphériques de stockage USB, et de « Ne faites confiance à aucun périphérique », qui consiste à se méfier du périphérique lui-même, ont été présentés comme des principes fondamentaux.

Paradigme de sécurité qui vérifie le fichier lui-même

Lors de cet événement, des cas concrets de mise en œuvre et des démonstrations techniques ont également été présentés, centrés sur la plateforme intégrée de sécurité des fichiers d'Opswat, MetaDefender.

MetaDefender est une plateforme de sécurité des fichiers préventive et basée sur le principe du « zéro confiance » qui effectue la vérification, la neutralisation, l'analyse et le contrôle dès l'entrée d'un fichier dans le système. Elle intègre une analyse antivirus multicanal, la désactivation et la reconstruction du contenu (CDR), l'analyse en environnement isolé (sandbox) basée sur l'IA, l'analyse des vulnérabilités des fichiers (FBVA), la prévention des pertes de données (DLP) et des fonctionnalités de sécurité pour les supports de stockage amovibles.

En particulier, en effectuant une vérification de sécurité multicouche sur les fichiers entrant par divers canaux tels que le courrier électronique, les téléchargements Web et les supports de stockage USB, il prend en charge l'identification et le blocage proactifs non seulement des logiciels malveillants connus, mais aussi des menaces non identifiées et des attaques zero-day.

Insec Security a prédit que la mise en place d'un système de sécurité des fichiers axé sur la prévention deviendra de plus en plus importante à l'avenir, compte tenu du nombre croissant d'attaques basées sur les fichiers et ciblant les infrastructures critiques dans les secteurs de la fabrication, de l'énergie, de la défense et des institutions publiques.

Like this:

Like Loading...
← 목록으로