Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

[Metaverse Expo] “Metaverse, the Key is Cloud Security”

Google 우선 소스Published2022.06.17 10:43

▲Megazone Cloud Team Leader Kim Jin-ho giving a presentation


Cloud Security Failures: Gartner: 99% User Fault
Team Leader Kim Jin-ho: “Security is a priority that cannot be compromised”

Beyond digital security, metaverse security is an issue that must be addressed from the early stages of technological development and market formation, and is gradually emerging as an urgent problem.

According to market research firm Gartner, 30% of organizations worldwide are expected to have a metaverse environment by 2026. Most cloud security incidents are due to configuration errors or user mistakes, and it is predicted that by 2025, at least 99% of cloud security failures will be the fault of users, not cloud providers.

On the 14th, the Korea Internet & Security Agency (KISA) held a metaverse security seminar. This event, which was designed to strengthen the security of the metaverse ecosystem, included sessions on cloud security, metaverse security framework, digital asset security, and metaverse distribution and payment platform security.

At the seminar held that day, MegaZone Cloud Team Leader Kim Jin-ho presented on the topic of cloud security, focusing on AWS.

When it comes to cloud security incidents, cloud providers are stating a shared responsibility model. AWS's area of responsibility is accidents related to facilities such as ▲network ▲hardware ▲software that run cloud services, and the user's area of responsibility is ▲operating system management such as updates and security patches ▲firewall configuration management ▲data management ▲asset classification and use of IAM tools that grant appropriate permissions, etc.

In the Azure cloud, the scope of responsibility between the provider and the user varies depending on SaaS, PaaS, IaaS, and on-premises. Team Leader Kim explained that the security manager must be aware of this and take action.

Team Leader Kim introduced the '5-EPICs', which are five core security areas that can be used to build cloud security: Identity & Access Management (IM), Detective Controls, Infrastructure Protection, Data Protection, and Breach Response. This is a security creation model that leverages numerous experiences and best practices in a cloud environment.

Looking at the response model by attack target, in the infrastructure and system sector, there is △IM for platform and system protection, △infrastructure protection against DDoS and web vulnerability attacks, and △detection control that enables rapid detection and response to authority theft or infrastructure attacks.

Team Leader Kim explained that in the network sector, the key solutions to respond to system hacking and client vulnerability attacks that target vulnerabilities in transmission and reception networks are infrastructure protection and data protection.

In order to respond to virtual asset theft and illegal copying, data falsification and leakage in the data sector, it is argued that data encryption and data rights management are the main priorities, and this corresponds to data protection and IM.

Finally, in the service sector, he judged that the areas of detection control and breach incident response are key cloud security areas to prevent non-application of security patches and leakage of personal information.

“While engineering priorities may vary depending on business decisions in workload design, security must not be compromised by other principles and priorities,” Kim emphasized.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
명세환 기자
명세환 기자