This page was machine-translated and may differ from the original. View original
Cybersecurity Crisis Response Drill, Participating Companies Respond Faster
Returning Participating Companies Show 4.4%p Lower Infection Rate Compared to New Participating Companies
DDoS Attack Response, Large Enterprises Respond Faster Than SMEs
DDoS Attack Response, Large Enterprises Respond Faster Than SMEs
Companies with experience in cybersecurity crisis response drills demonstrated better cybersecurity crisis response capabilities in DDoS attacks, email hacking, and other cyber threats.
The Ministry of Science and ICT announced the results of the second half cybersecurity crisis response drill conducted in November last year.
In the hacking email response drill, the infection rate of returning participating companies was 3.6%, lower than the 8.0% of newly participating companies, confirming that response capabilities have improved.
It was found that large enterprises respond to DDoS attacks faster than SMEs.
Among 50 companies that participated in simulated hacking infiltration training, 32 companies were confirmed to be capable of critical information theft, and related vulnerabilities were immediately removed.
As cyber threat crises have recently intensified, the Ministry of Science and ICT conducted simulated drills targeting private enterprises in the same manner as actual cyber attacks in cooperation with the Korea Internet & Security Agency (KISA).
The second half 2021 simulated drill was conducted from November 1st last year for approximately three weeks, with the participation of 285 companies and 93,257 employees.
The simulated drill consisted of △checking response procedures following hacking email transmission △DDoS attack and recovery checking △simulated infiltration targeting companies' websites and servers.
■Checking Response Procedures Following Hacking Email Transmission
The hacking email transmission and response procedure checking drill was conducted targeting employees.
The drill was conducted by sending hacking emails impersonating recent issues or internal employees such as △program update notices △guidance on in-house COVID-19 vaccination targets, and inducing employees to install malware by reading the emails and clicking on attachments.
The hacking email open rate was 16.7% and the infection rate was 5.4%, each decreasing by 9.1%p and 2.2%p compared to the first half of the year.
The infection rate of returning participating companies was 3.6%, lower than the 8.0% infection rate of newly participating companies, indicating that response capabilities have improved.
The Ministry of Science and ICT additionally conducted information security training including ransomware cases, prevention measures, and recovery procedures.
■DDoS Attack and Recovery Checking
The DDoS drill was conducted by performing actual DDoS attacks on the websites of 44 participating companies.
Detection time and response time of each company's security equipment were measured, and response capabilities against database load attacks and other threats were checked.
Large enterprises showed relatively superior performance compared to SMEs (detection shortened by 4 minutes, response by 7 minutes).
Accordingly, the Ministry of Science and ICT provided guidance on response capability enhancement training for SME security personnel who showed insufficient DDoS attack response, and information on utilizing KISA's DDoS Cyber Evacuation Center.
■Simulated Infiltration Targeting Companies' Websites and Servers
The simulated infiltration drill was conducted by having white hat hackers attempt to infiltrate company servers to verify security threat exposure.
Among a total of 45 companies, 40 companies discovered and removed 163 hidden web vulnerabilities, preventing hacking threats in advance.
In particular, simulated infiltration attempts were conducted targeting companies' web servers and business servers.
Among 50 participating companies, 32 companies (exceeding 60%) were confirmed to be capable of acquiring system control rights and stealing critical information, and related vulnerabilities were immediately removed.
Hong Jin-bae, Director of Information Protection Network Policy, stated: "Following the discovery of critical vulnerabilities in Apache Log4j, cyber threats are escalating globally," and emphasized that "many companies actively participate in government-conducted simulated drills to minimize damage."
Meanwhile, the Ministry of Science and ICT plans to develop scenarios such as increased threats targeting IoT, theft of metaverse user information, and illegal sales following privilege theft related to NFTs, which were derived from this year's cyber threat outlook analysis.
Additionally, it announced plans to establish a customized continuous hacking simulated drill platform and guide companies participating in the drills to note corporate activities for information protection in information protection disclosures.
The Ministry of Science and ICT announced the results of the second half cybersecurity crisis response drill conducted in November last year.
In the hacking email response drill, the infection rate of returning participating companies was 3.6%, lower than the 8.0% of newly participating companies, confirming that response capabilities have improved.
It was found that large enterprises respond to DDoS attacks faster than SMEs.
Among 50 companies that participated in simulated hacking infiltration training, 32 companies were confirmed to be capable of critical information theft, and related vulnerabilities were immediately removed.
As cyber threat crises have recently intensified, the Ministry of Science and ICT conducted simulated drills targeting private enterprises in the same manner as actual cyber attacks in cooperation with the Korea Internet & Security Agency (KISA).
The second half 2021 simulated drill was conducted from November 1st last year for approximately three weeks, with the participation of 285 companies and 93,257 employees.
The simulated drill consisted of △checking response procedures following hacking email transmission △DDoS attack and recovery checking △simulated infiltration targeting companies' websites and servers.
■Checking Response Procedures Following Hacking Email Transmission
The hacking email transmission and response procedure checking drill was conducted targeting employees.
The drill was conducted by sending hacking emails impersonating recent issues or internal employees such as △program update notices △guidance on in-house COVID-19 vaccination targets, and inducing employees to install malware by reading the emails and clicking on attachments.
The hacking email open rate was 16.7% and the infection rate was 5.4%, each decreasing by 9.1%p and 2.2%p compared to the first half of the year.
The infection rate of returning participating companies was 3.6%, lower than the 8.0% infection rate of newly participating companies, indicating that response capabilities have improved.
The Ministry of Science and ICT additionally conducted information security training including ransomware cases, prevention measures, and recovery procedures.
■DDoS Attack and Recovery Checking
The DDoS drill was conducted by performing actual DDoS attacks on the websites of 44 participating companies.
Detection time and response time of each company's security equipment were measured, and response capabilities against database load attacks and other threats were checked.
Large enterprises showed relatively superior performance compared to SMEs (detection shortened by 4 minutes, response by 7 minutes).
Accordingly, the Ministry of Science and ICT provided guidance on response capability enhancement training for SME security personnel who showed insufficient DDoS attack response, and information on utilizing KISA's DDoS Cyber Evacuation Center.
■Simulated Infiltration Targeting Companies' Websites and Servers
The simulated infiltration drill was conducted by having white hat hackers attempt to infiltrate company servers to verify security threat exposure.
Among a total of 45 companies, 40 companies discovered and removed 163 hidden web vulnerabilities, preventing hacking threats in advance.
In particular, simulated infiltration attempts were conducted targeting companies' web servers and business servers.
Among 50 participating companies, 32 companies (exceeding 60%) were confirmed to be capable of acquiring system control rights and stealing critical information, and related vulnerabilities were immediately removed.
Hong Jin-bae, Director of Information Protection Network Policy, stated: "Following the discovery of critical vulnerabilities in Apache Log4j, cyber threats are escalating globally," and emphasized that "many companies actively participate in government-conducted simulated drills to minimize damage."
Meanwhile, the Ministry of Science and ICT plans to develop scenarios such as increased threats targeting IoT, theft of metaverse user information, and illegal sales following privilege theft related to NFTs, which were derived from this year's cyber threat outlook analysis.
Additionally, it announced plans to establish a customized continuous hacking simulated drill platform and guide companies participating in the drills to note corporate activities for information protection in information protection disclosures.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.















