This page was machine-translated and may differ from the original. View original

▲At LG CNS Summit 2022, information on shifting security paradigms and responses was shared. (Photo: LG CNS Summit 2022 capture)
Control and Infrastructure Industries See a Surge in Hacking Attacks
Deepfakes will become a significant threat within five years.
In addition to discussing domestic and international security trends, the forum provided an opportunity to hear about the application of the latest security technologies, including OT security and AI security, as well as new risks.
At the LG CNS Summit 2022 held on the 25th, experts, including Professor Jeong Su-hwan of the Department of Electronic and Information Engineering at Soongsil University, shared information on the changing security paradigm and responses under the theme of "AI and OT: Examining the Latest Global Security Trends."
This discussion was attended by Gwak Gyu-bok, a specialist in the LG CNS Security Technology Strategy Team, Jeong Su-hwan, a professor in the Department of Electronic and Information Engineering at Soongsil University, Lee Hyang-jin, team leader of the KISA Infrastructure Protection Team, and Kim Chang-hee, team leader of the AhnLab Product Planning Team.
Expert Commissioner Kwak Gyu-bok said, “Cyberwarfare has emerged as the biggest issue both domestically and internationally. “The war in Ukraine is changing the security paradigm,” he said. “With the expansion of cyber warfare, attacks aimed at destroying systems between countries are rapidly increasing, and Korea is also strengthening its response system at the government level.”
Team Leader Kim Chang-hee reported that, according to AhnLab's monitoring results, the industry with the highest attack rate compared to general industries in the global market was control facilities and infrastructure, accounting for 24.4%. The domestic situation is similar, with the average industry experiencing a 12-17% increase in attacks, while attacks on control and infrastructure increased by 29.5%.
When asked about attacks on industrial infrastructure, Team Leader Lee Hyang-jin responded, "There have been no official announcements of attacks on major information and communications infrastructure in Korea." He continued, "The most recent major incident overseas was the ransomware attack on Colonial Pipeline, a US pipeline company, which raised alarms." He went on to explain that while damage incidents are occurring at small and medium-sized smart factories in Korea, some are not disclosed for business reasons.
Team Leader Kim Chang-hee stated, "These threats have significantly increased the number of measures companies must take to address them." With remote work becoming the norm due to COVID-19, external contact points have increased, diversifying attack vectors. Furthermore, many industries are using outdated operating systems with outdated security support, increasing the risk of hacking due to weak perimeter security. He emphasized the need to maintain fundamental perimeter security and consistently implement measures to address permissions and network connections.
Professor Jeong Su-hwan cited deepfakes as one of the latest security threat trends. During the Ukrainian War, a video appeared to show President Zelensky surrendering, and this was also created using deepfake technology. Successful cases of voice phishing using deepfake technology have also been confirmed. Professor Jeong predicted that deepfake would become a significant threat within five years.
Professor Jeong, regarding the application of new AI security technologies, stated that AI is essential to security. Security event data continues to grow, and analyzing it all manually is impossible. For this reason, AI is being used for security control and malware and network traffic attack detection.
He then cited updating AI systems to prepare for new attack patterns, unlike those seen in the past, as a key consideration when applying AI to security technologies. He expressed the opinion that, given the relatively recent adoption of AI in the security field, building a mature AI system is a priority.
Team Leader Kim Chang-hee stated that in real-world industrial settings, mishandling a system can impact availability, making it difficult for non-experts to access equipment systems. He continued that OT security requires significant time, as it requires research and collaboration with manufacturers. However, he added that in areas like smart factories for small and medium-sized enterprises (SMEs), the diverse environments and numerous constraints make it difficult to access.
The new paradigm of information security has shifted the IT environment of businesses and organizations in the wake of COVID-19. While traditional security relied on authentication and access control, distinguishing between internal and external environments, the current cloud and other technologies make it difficult to distinguish between internal and external environments.
In this trend, Professor Jeong said that the paradigm is shifting to a 'zero trust'-based approach that allows access through thorough verification. To achieve 'zero trust', security mechanisms must be automated because a huge amount of data must be verified.
Taking advantage of this, hackers have begun exploiting vulnerabilities in AI itself. Cases have been reported where AI training data and decision-making data were corrupted, preventing accurate decisions from being made. Such attacks could have devastating consequences for smart cars and smart factories.
Professor Jeong predicted that countermeasures against dysfunction arising from AI-based security automation and improving the reliability of AI systems themselves will become important issues in the future.
At the LG CNS Summit 2022 held on the 25th, experts, including Professor Jeong Su-hwan of the Department of Electronic and Information Engineering at Soongsil University, shared information on the changing security paradigm and responses under the theme of "AI and OT: Examining the Latest Global Security Trends."
This discussion was attended by Gwak Gyu-bok, a specialist in the LG CNS Security Technology Strategy Team, Jeong Su-hwan, a professor in the Department of Electronic and Information Engineering at Soongsil University, Lee Hyang-jin, team leader of the KISA Infrastructure Protection Team, and Kim Chang-hee, team leader of the AhnLab Product Planning Team.
Expert Commissioner Kwak Gyu-bok said, “Cyberwarfare has emerged as the biggest issue both domestically and internationally. “The war in Ukraine is changing the security paradigm,” he said. “With the expansion of cyber warfare, attacks aimed at destroying systems between countries are rapidly increasing, and Korea is also strengthening its response system at the government level.”
Team Leader Kim Chang-hee reported that, according to AhnLab's monitoring results, the industry with the highest attack rate compared to general industries in the global market was control facilities and infrastructure, accounting for 24.4%. The domestic situation is similar, with the average industry experiencing a 12-17% increase in attacks, while attacks on control and infrastructure increased by 29.5%.
When asked about attacks on industrial infrastructure, Team Leader Lee Hyang-jin responded, "There have been no official announcements of attacks on major information and communications infrastructure in Korea." He continued, "The most recent major incident overseas was the ransomware attack on Colonial Pipeline, a US pipeline company, which raised alarms." He went on to explain that while damage incidents are occurring at small and medium-sized smart factories in Korea, some are not disclosed for business reasons.
Team Leader Kim Chang-hee stated, "These threats have significantly increased the number of measures companies must take to address them." With remote work becoming the norm due to COVID-19, external contact points have increased, diversifying attack vectors. Furthermore, many industries are using outdated operating systems with outdated security support, increasing the risk of hacking due to weak perimeter security. He emphasized the need to maintain fundamental perimeter security and consistently implement measures to address permissions and network connections.
Professor Jeong Su-hwan cited deepfakes as one of the latest security threat trends. During the Ukrainian War, a video appeared to show President Zelensky surrendering, and this was also created using deepfake technology. Successful cases of voice phishing using deepfake technology have also been confirmed. Professor Jeong predicted that deepfake would become a significant threat within five years.
Professor Jeong, regarding the application of new AI security technologies, stated that AI is essential to security. Security event data continues to grow, and analyzing it all manually is impossible. For this reason, AI is being used for security control and malware and network traffic attack detection.
He then cited updating AI systems to prepare for new attack patterns, unlike those seen in the past, as a key consideration when applying AI to security technologies. He expressed the opinion that, given the relatively recent adoption of AI in the security field, building a mature AI system is a priority.
Team Leader Kim Chang-hee stated that in real-world industrial settings, mishandling a system can impact availability, making it difficult for non-experts to access equipment systems. He continued that OT security requires significant time, as it requires research and collaboration with manufacturers. However, he added that in areas like smart factories for small and medium-sized enterprises (SMEs), the diverse environments and numerous constraints make it difficult to access.
The new paradigm of information security has shifted the IT environment of businesses and organizations in the wake of COVID-19. While traditional security relied on authentication and access control, distinguishing between internal and external environments, the current cloud and other technologies make it difficult to distinguish between internal and external environments.
In this trend, Professor Jeong said that the paradigm is shifting to a 'zero trust'-based approach that allows access through thorough verification. To achieve 'zero trust', security mechanisms must be automated because a huge amount of data must be verified.
Taking advantage of this, hackers have begun exploiting vulnerabilities in AI itself. Cases have been reported where AI training data and decision-making data were corrupted, preventing accurate decisions from being made. Such attacks could have devastating consequences for smart cars and smart factories.
Professor Jeong predicted that countermeasures against dysfunction arising from AI-based security automation and improving the reliability of AI systems themselves will become important issues in the future.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















