🔗 원문 전체 보기 → Venturesquare.net

요약
인포시즈가 그래프 기반 AI 보안 솔루션 ‘GOS’를 출시하고 국내 반도체 대기업에 전사 공급했다. GOS는 계정·프로세스·파일·접속 등의 관계를 그래프로 분석해 정상적인 업무 패턴에서 벗어난 행위를 탐지하고 공격 경로와 판단 근거를 제공한다. 그래프 ML로 위험 후보를 먼저 선별해 LLM 분석 대상을 전체 행위 그래프의 0.068% 수준으로 줄이는 구조를 적용했다. 기존 SIEM·SOAR와 연동해 기업의 기존 보안 인프라 위에 AI 분석 계층을 추가할 수 있…
본문
- 계정·프로세스·파일·접속 관계 그래프로 연결해 평소와 다른 행위 탐지…공격 시작점·이동 경로까지 분석
- 그래프 ML로 위험 후보 먼저 추린 뒤 애널라이저 LLM이 2차 검증…국내 반도체 대기업 전사 공급
기업 보안 시스템이 수집하는 로그가 늘어날수록 모든 경보를 사람이 확인하거나 LLM으로 분석하는 방식에는 비용과 처리량의 한계가 생긴다. 이미 알려진 공격 유형이나 사전에 설정한 규칙만으로는 정상적인 업무와 비슷하게 움직이는 새로운 공격을 구분하기도 어렵다. 인포시즈가 기업의 계정과 프로세스, 파일, 접속 사이의 관계를 그래프로 만든 뒤 평소 업무 흐름에서 벗어난 행동을 먼저 추려내고 일부만 LLM으로 재검증하는 보안 솔루션을 내놨다. 전체 행위 그래프 가운데 LLM이 분석할 대상을 0.068% 수준으로 줄이는 구조가 핵심이다.
온톨로지 기반 엔터프라이즈 AI 기업 인포시즈(대표 탁정수)는 그래프 기반 AI 보안 솔루션 ‘고스(GOS, Graph Optimized Security)’를 정식 출시하고 국내 반도체 대기업에 전사 공급했다.

GOS는 사전에 등록한 공격 유형과 탐지 규칙을 중심으로 위협을 찾는 방식과 달리 조직의 업무 패턴과 데이터 사이 관계를 분석해 정상 범위를 벗어난 행동을 탐지하도록 설계됐다.
계정과 프로세스, 파일, 접속 등 대규모 보안 로그에서 나타나는 관계를 그래프로 연결해 개별 로그만으로 확인하기 어려운 공격의 시작점과 이동 경로, 연관 행위를 함께 분석한다.
모든 로그를 LLM에 넣지 않는다…그래프 ML로 위험 후보부터 압축
GOS의 또 다른 특징은 그래프 머신러닝(Graph ML)과 LLM의 역할을 나눴다는 점이다. 자체 개발한 그래프 ML이 대규모 보안 로그를 먼저 분석해 위협 가능성이 높은 후보를 선별하면 ‘애널라이저 LLM(Analyzer LLM)’이 해당 후보의 위험 가능성과 행위 맥락을 다시 분석한다.
인포시즈는 모든 로그를 상용 LLM으로 분석할 경우 대규모 비용이 발생할 수 있다는 점을 고려해 LLM 분석 범위를 전체 행위 그래프의 0.068% 수준으로 좁혔다고 설명했다. 이를 통해 LLM 호출량과 운영 비용을 줄이면서 그래프 분석과 LLM의 맥락 분석을 결합하는 구조다.
기존 보안 인프라를 교체하지 않고 연결할 수도 있다. SIEM(Security Information and Event Management)이 수집한 로그를 GOS가 그래프로 분석해 위험도와 공격 경로, 판단 근거를 제공하고 검증된 위협 정보는 SOAR(Security Orchestration, Automation and Response)의 대응 절차와 연계할 수 있다. 계정 잠금과 단말 격리, 통신 차단 등의 실제 조치는 기존 SOAR 체계를 통해 수행하는 방식이다.
회사는 대기업 EDR(Endpoint Detection and Response) 환경에서 GOS 성능을 검증했다고 밝혔다. 인포시즈 자체 검증 결과 별도 탐지 규칙을 등록하지 않은 상태에서 검증 대상 위협을 모두 탐지해 해당 테스트에서 미탐률 0%를 기록했고 정상 로그의 99.998%를 분석 대상에서 제외했다. 기존 탐지 체계에서 경보가 발생하지 않았던 형태의 공격 행위도 추가로 식별했다는 설명이다. 다만 이 수치는 특정 기업 환경에서 수행한 회사 측 성능 검증 결과다.
GOS는 인포시즈가 기존 엔터프라이즈 AI 사업에서 활용해온 관계·맥락 분석 기술을 보안 영역에 적용한 제품이다. 회사는 온톨로지 기반 엔터프라이즈 AI 솔루션 ‘액시엄(Axiom)’과 산업 도면을 지식 그래프로 변환하는 ‘델타플로우(DELTAflow)’도 운영하고 있다.
탁정수 인포시즈 대표는 “기업 보안의 핵심은 더 많은 경보를 생성하는 것이 아니라 실제 위협을 놓치지 않는 동시에 정상적인 업무를 방해하지 않는 정확한 판단 체계를 만드는 데 있다”며 “이번 프로젝트 수주를 시작으로 대규모 보안 로그와 복잡한 업무 환경을 보유한 엔터프라이즈 기업을 대상으로 솔루션 적용을 확대할 계획”이라고 말했다.
Like this:
Like Loading...Related
InfoSeeds: Only 0.068% of Security Logs Re-examined by LLMs… Launches Graph AI 'GOS'
As the volume of logs collected by corporate security systems increases, relying on human verification or LLM analysis for every alert faces limitations in terms of cost and throughput. It is also difficult to distinguish new attacks that mimic normal business operations using only known attack types or pre-configured rules. InfoSeeds has introduced a security solution that graphs the relationships between corporate accounts, processes, files, and connections to first identify behaviors that deviate from the usual workflow, and then re-verifies only a portion of them using LLM. The core of the solution is a structure that reduces the scope of LLM analysis to just 0.068% of the total behavior graph.
InfoSeas (CEO Tak Jeong-su), an ontology-based enterprise AI company, officially launched its graph-based AI security solution 'GOS (Graph Optimized Security)' and supplied it company-wide to a major domestic semiconductor company.

Unlike threat detection methods based on pre-registered attack types and detection rules, GOS is designed to detect behavior outside the normal range by analyzing the relationship between an organization's business patterns and data.
It connects the relationships appearing in large-scale security logs—such as accounts, processes, files, and connections—into graphs to analyze the starting points, movement paths, and associated behaviors of attacks that are difficult to identify with individual logs alone.
Do not put all logs into LLM… Compress risk candidates first using Graph ML
Another feature of GOS is that it separates the roles of Graph Machine Learning (Graph ML) and LLM. Once the proprietary Graph ML first analyzes large-scale security logs to identify candidates with a high probability of threat, the 'Analyzer LLM' re-analyzes the risk potential and behavioral context of those candidates.
InfoSeeds explained that it narrowed the scope of LLM analysis to 0.068% of the entire behavior graph, considering that analyzing all logs with a commercial LLM could incur massive costs. This structure combines graph analysis with LLM context analysis while reducing LLM call volume and operational costs.
It is also possible to connect without replacing the existing security infrastructure. GOS analyzes logs collected by SIEM (Security Information and Event Management) using graphs to provide risk levels, attack paths, and grounds for judgment, and verified threat information can be linked with the response procedures of SOAR (Security Orchestration, Automation and Response). Actual measures, such as account locking, endpoint isolation, and communication blocking, are executed through the existing SOAR framework.
The company announced that it verified the performance of GOS in an enterprise EDR (Endpoint Detection and Response) environment. According to InfoSeeds' own verification results, it detected all targets without registering separate detection rules, recording a 0% false negative rate in the test and excluding 99.998% of normal logs from analysis. The company explained that it additionally identified types of attack behaviors that did not trigger alerts in existing detection systems. However, these figures are the results of the company's performance verification conducted in a specific corporate environment.
GOS is a product that applies the relationship and context analysis technologies InfoSeeds has utilized in its existing enterprise AI business to the security domain. The company also operates 'Axiom,' an ontology-based enterprise AI solution, and 'DELTAflow,' which converts industrial drawings into knowledge graphs.
Tak Jeong-soo, CEO of InfoSeeds, stated, “The core of enterprise security lies not in generating more alerts, but in establishing an accurate judgment system that does not miss actual threats while avoiding disruption to normal business operations.” He added, “Starting with this project win, we plan to expand the application of our solutions to enterprise companies with large-scale security logs and complex business environments.”
インフォシーズ、セキュリティログ0.068%だけLLMが見直す…グラフAI「GOS」リリース
企業セキュリティシステムが収集するログが増えるほど、すべてのアラームを人が確認したりLLMで分析したりする方法にはコストとスループットの限界が生じる。既知の攻撃タイプや事前に設定したルールだけでは、通常の業務と同様に動く新しい攻撃を区別することも難しい。インフォシーズが企業のアカウントとプロセス、ファイル、接続との関係をグラフにした後、普段の業務フローから外れた行動を先に選び出し、一部だけLLMで再検証するセキュリティソリューションを出した。全体行為グラフの中でLLMが分析する対象を0.068%レベルに減らす構造が核心だ。
オントロジーベースのエンタープライズAI企業インフォシーズ(代表タクジョンス)は、グラフベースのAIセキュリティソリューション「GOS、Graph Optimized Security」を正式発売し、国内半導体大企業に戦士供給した。

GOSは、事前に登録した攻撃タイプと検出ルールを中心に脅威を探す方法とは異なり、組織の業務パターンとデータの関係を分析して正常範囲外の行動を検出するように設計された。
アカウントとプロセス、ファイル、接続など大規模なセキュリティログに現れる関係をグラフで連結し、個別ログだけで確認しにくい攻撃の始点と移動経路、関連行為を一緒に分析する。
すべてのログをLLMに入れない…グラフMLでリスク候補から圧縮
GOSのもう一つの特徴は、グラフ機械学習(Graph ML)とLLMの役割を分けたという点だ。自己開発したグラフMLが大規模なセキュリティログを先に分析して脅威の可能性が高い候補を選別すると、「アナライザLLM(Analyzer LLM)」が該当候補のリスク可能性と行為コンテキストを再分析する。
インフォシーズは、すべてのログを商用LLMで分析すると大規模なコストが発生する可能性があることを考慮して、LLM分析の範囲を全体行為グラフの0.068%レベルに絞ったと説明した。これにより、LLM呼び出し量と運用コストを削減しながら、グラフ分析とLLMのコンテキスト分析を組み合わせる構造だ。
既存のセキュリティインフラストラクチャを交換せずに接続することもできます。 SIEM(Security Information and Event Management)が収集したログをGOSがグラフで分析し、危険度と攻撃経路、判断根拠を提供し、検証された脅威情報はSOAR(Security Orchestration、Automation and Response)の対応手続きと連携することができる。アカウントのロック、端末の分離、通信の遮断などの実際の措置は、既存のSOARスキームを介して実行する方式である。
同社は大企業EDR(Endpoint Detection and Response)環境でGOSの性能を検証したと明らかにした。インフォシーズ自体検証の結果、別途検出ルールを登録していない状態で検証対象脅威をすべて検出し、該当テストで未発見率0%を記録し、正常ログの99.998%を分析対象から除外した。既存の検知体系で警報が発生しなかった形態の攻撃行為もさらに識別したという説明だ。ただし、この数値は特定の企業環境で行った会社側の性能検証結果だ。
GOSは、インフォシーズが既存のエンタープライズAI事業で活用してきた関係・コンテキスト分析技術をセキュリティ領域に適用した製品だ。同社はオントロジーベースのエンタープライズAIソリューション「アクシオム(Axiom)」と産業図面を知識グラフに変換する「デルタフロー(DELTAflow)」も運営している。
タク・ジョンスインフォシーズ代表は「企業セキュリティの核心はより多くのアラームを生成するのではなく、実際の脅威を逃さないと同時に正常な業務を妨げない正確な判断体系を作ることにある」とし「今回のプロジェクト受注を皮切りに大規模なセキュリティログと複雑な業務環境を保有するエンタープライズ企業を対象にソリューション適用を拡大する計画」と話した。
InfoSeeds:LLM 仅重新审查了 0.068% 的安全日志……推出图 AI“GOS”
随着企业安全系统收集的日志量不断增长,仅依靠人工验证或LLM分析来处理每个警报在成本和吞吐量方面都存在局限性。此外,仅使用已知的攻击类型或预配置规则也难以区分模仿正常业务操作的新型攻击。InfoSeeds推出了一种安全解决方案,该方案绘制企业帐户、流程、文件和连接之间的关系图,首先识别偏离常规工作流程的行为,然后仅使用LLM对其中一部分进行复核。该解决方案的核心在于一种结构,它将LLM分析的范围缩小到仅占整个行为图的0.068%。
基于本体的企业人工智能公司 InfoSeas(CEO Tak Jeong-su)正式推出其基于图的人工智能安全解决方案“GOS(Graph Optimized Security)”,并向一家国内大型半导体公司提供了全公司范围的解决方案。

与基于预先注册的攻击类型和检测规则的威胁检测方法不同,GOS 旨在通过分析组织业务模式和数据之间的关系来检测超出正常范围的行为。
它将大规模安全日志中出现的关系(例如帐户、进程、文件和连接)连接成图表,以分析攻击的起点、移动路径和相关行为,而这些攻击仅凭单个日志很难识别。
不要将所有日志都放入LLM……首先使用图机器学习压缩风险候选对象。
GOS 的另一个特点是它将图机器学习 (Graph ML) 和 LLM 的角色分开。专有的 Graph ML 首先分析大规模安全日志,识别出具有高威胁概率的候选对象,然后“分析器 LLM”会对这些候选对象的风险潜力和行为背景进行重新分析。
InfoSeeds解释说,考虑到使用商业LLM分析所有日志可能会产生巨额成本,他们将LLM分析的范围缩小到整个行为图的0.068%。这种结构将图分析与LLM上下文分析相结合,同时减少了LLM调用量和运营成本。
此外,无需替换现有安全基础设施即可实现连接。GOS 利用图表分析 SIEM(安全信息和事件管理)收集的日志,提供风险级别、攻击路径和判断依据,并将经核实的威胁信息与 SOAR(安全编排、自动化和响应)的响应流程关联起来。账户锁定、端点隔离和通信阻断等实际措施均通过现有的 SOAR 框架执行。
该公司宣布,已在企业级EDR(端点检测与响应)环境中验证了GOS的性能。根据InfoSeeds的验证结果,GOS无需设置额外的检测规则即可检测到所有目标,测试中漏报率为0%,并且排除了99.998%的正常日志。该公司解释说,GOS还识别出一些现有检测系统无法触发警报的攻击行为类型。然而,这些数据是该公司在特定企业环境中进行的性能验证结果。
GOS是一款产品,它将InfoSeeds公司在其现有企业人工智能业务中使用的关系和上下文分析技术应用于安全领域。该公司还运营着基于本体的企业人工智能解决方案“Axiom”以及将工业图纸转换为知识图谱的“DELTAflow”。
InfoSeeds首席执行官卓正洙表示:“企业安全的核心不在于生成更多警报,而在于建立一套精准的判断系统,既能识别实际威胁,又能避免对正常业务运营造成干扰。” 他补充道:“从赢得这个项目开始,我们计划将解决方案的应用范围扩展到拥有大规模安全日志和复杂业务环境的企业。”
InfoSeeds : Seuls 0,068 % des journaux de sécurité sont réexaminés par des LLM… Lancement de « GOS », une plateforme d’IA graphique.
Face à l'augmentation du volume de journaux collectés par les systèmes de sécurité d'entreprise, le recours systématique à la vérification humaine ou à l'analyse LLM pour chaque alerte présente des limites en termes de coût et de débit. Il est également difficile de distinguer les nouvelles attaques imitant les opérations commerciales normales en se basant uniquement sur des types d'attaques connus ou des règles préconfigurées. InfoSeeds a développé une solution de sécurité qui représente graphiquement les relations entre les comptes, processus, fichiers et connexions de l'entreprise afin d'identifier les comportements anormaux, puis de revérifier seulement une partie d'entre eux à l'aide de l'analyse LLM. Au cœur de cette solution se trouve une structure qui réduit le périmètre de l'analyse LLM à seulement 0,068 % du graphe comportemental total.
InfoSeas (PDG Tak Jeong-su), une société d'IA d'entreprise basée sur l'ontologie, a officiellement lancé sa solution de sécurité IA basée sur les graphes « GOS (Graph Optimized Security) » et l'a fournie à l'échelle de l'entreprise à une grande société nationale de semi-conducteurs.

Contrairement aux méthodes de détection des menaces basées sur des types d'attaques et des règles de détection préenregistrées, GOS est conçu pour détecter les comportements anormaux en analysant la relation entre les modèles commerciaux et les données d'une organisation.
Il relie les relations apparaissant dans les journaux de sécurité à grande échelle (comptes, processus, fichiers et connexions) sous forme de graphiques afin d'analyser les points de départ, les trajectoires et les comportements associés des attaques difficiles à identifier avec les seuls journaux individuels.
N’intégrez pas tous les journaux dans LLM… Commencez par compresser les candidats à risque à l’aide de Graph ML.
Une autre caractéristique de GOS est la séparation des rôles entre l'apprentissage automatique sur graphes (Graph ML) et le LLM. Après une première analyse par le Graph ML propriétaire de journaux de sécurité à grande échelle afin d'identifier les candidats présentant une forte probabilité de menace, le module « Analyzer LLM » réanalyse le potentiel de risque et le contexte comportemental de ces candidats.
InfoSeeds a expliqué avoir limité le périmètre de l'analyse LLM à 0,068 % du graphe de comportement total, considérant que l'analyse de tous les journaux avec un outil LLM commercial engendrerait des coûts considérables. Cette structure combine l'analyse de graphes et l'analyse contextuelle LLM, tout en réduisant le volume d'appels LLM et les coûts opérationnels.
Il est également possible de se connecter sans remplacer l'infrastructure de sécurité existante. GOS analyse les journaux collectés par le SIEM (Gestion des informations et des événements de sécurité) à l'aide de graphiques afin de fournir des niveaux de risque, des vecteurs d'attaque et des éléments de décision. Les informations vérifiées sur les menaces peuvent être associées aux procédures de réponse du SOAR (Orchestration, automatisation et réponse de sécurité). Les mesures concrètes, telles que le verrouillage des comptes, l'isolation des terminaux et le blocage des communications, sont exécutées via l'infrastructure SOAR existante.
La société a annoncé avoir validé les performances de GOS dans un environnement EDR (Endpoint Detection and Response) d'entreprise. D'après les résultats de validation d'InfoSeeds, GOS a détecté toutes les cibles sans nécessiter de règles de détection supplémentaires, affichant un taux de faux négatifs de 0 % et excluant 99,998 % des journaux normaux de l'analyse. La société a également indiqué avoir identifié des types de comportements d'attaque qui ne déclenchaient pas d'alertes dans les systèmes de détection existants. Ces chiffres sont toutefois issus d'une validation de performance réalisée dans un environnement d'entreprise spécifique.
GOS est un produit qui applique au domaine de la sécurité les technologies d'analyse des relations et du contexte qu'InfoSeeds utilise déjà dans ses activités d'IA d'entreprise. La société propose également « Axiom », une solution d'IA d'entreprise basée sur une ontologie, et « DELTAflow », qui convertit les dessins industriels en graphes de connaissances.
Tak Jeong-soo, PDG d'InfoSeeds, a déclaré : « La sécurité d'entreprise repose avant tout sur la capacité à identifier les menaces réelles sans perturber l'activité. » Il a ajouté : « Grâce à ce nouveau projet, nous prévoyons d'étendre l'application de nos solutions aux grandes entreprises disposant de journaux de sécurité volumineux et d'environnements complexes. »