This page was machine-translated and may differ from the original. View original

“ChatGPT, a shield or spear for cybersecurity”

Google 우선 소스Published2023.05.04 11:30

Differentiation from existing AI… Coexistence of positive and negative influences
ChatGPT New Cyber Attacks ↑135%… Countermeasures Must Be Prepared
LG CNS-MS Join Hands to Build Generative AI Security Architecture

As the global competition for AI technology hegemony intensifies, consideration and response to cybersecurity aspects of ultra-large AI technologies such as ChatGPT are required as next-generation core competencies.

At the 21st 'Hacking Security Seminar' held at the National Assembly Members' Hall on the 3rd, KT Vice President Seok-Joong Kim gave a presentation on the topic of 'Opportunities and Threats of ChatGPT' and discussed the opportunities and threats that ChatGPT poses in cybersecurity.

Vice Minister Kim said, “ChatGPT, which is different from existing AI, can have both positive and negative effects,” and argued, “ChatGPT should be used as a tool to eliminate security threats in advance and improve cybersecurity.”

Since the ChatGPT craze that surpassed 100 million users earlier this year swept the world, global big tech companies such as MS, Google, and Meta have been focusing on creating more sophisticated large-scale language models by investing in numerous GPUs.

ChatGPT, which can communicate naturally with humans, is a type of chatbot service, and past language models are widely used as statistical techniques.Unlike before, GPT has been transformed into a model based on an artificial neural network.

However, ChatGPT, which is being utilized in various fields, has both a positive aspect in terms of cybersecurity in that it can actively utilize AI to strengthen security, and a negative aspect in that it can pose a threat to the security industry as a malware generation program language.

AI is most useful in virtual reality. ChatGPT can simulate the connection part on the OS network to configure the virtual environment. It can also easily access the programming language to perform tasks such as requirement analysis in digital forensics. It is proficient in coding tasks such as malware analysis, annotation work, and code vulnerability analysis.

On the other hand, there is also a threat from ChatGPT. ChatGPT does not respond to ethical issues, but methods to resolve them are being devised. In addition, users’ personal information can lead to phishing scams, such as the disclosure of hacking codes and the leakage of sensitive data such as company payment information.

There has also been an increase in security threats in the form of stealing credit card and financial information when downloading extensions related to ChatGPT. Vice President Kim added, “Since ChatGPT, the number of new social engineering attacks has increased by 135%, in line with the trend of adoption in the advertising sector.”

Vice President Kim predicted that the global generative AI trend will continue for the time being as the recent advancement of AI technology has reduced labor costs and increased development speed, and that countermeasures such as establishing a legal system to crack down on abuse cases are necessary so that ChatGPT can help improve security across industries undergoing digital transformation.

■ Meta, Add a Business Account to Facebook

According to foreign media, Meta recently reported that malware disguised as ChatGPT and similar AI software has increased rapidly. This is a method of stealing user account credentials when downloading mobile apps disguised as ChatGPT tools. In particular, Meta said that there has been an increase in cases targeting business managers and personal accounts of platform users on Facebook.

To combat this, Meta plans to introduce a new type of business account called 'Meta Work' in the future, which will allow users to access Facebook Business Manager tools without a personal Facebook account.

Meta is also releasing tools to help businesses prevent malware. Step-by-step instructions on how to identify and remove malware, including using third-party antivirus tools.

■ KT·LG CNS accelerates AI-based security business

On the 11th, KT commercialized the 'AI Intelligent Persistent Threat (APT) Analysis Technology' solution that analyzes users' emails based on AI and defends against new APT hacking attacks that exploit vulnerabilities.

It is based on over 200 million email data analyzed annually through KT's AI analysis platform, and the DB has been optimized to fit the domestic environment. Accordingly, the detection accuracy is up to 22% higher than that of overseas security companies, and the malware detection speed is up to 180 times faster than the existing dynamic analysis method.

KT said, “In order to effectively defend against APT attacks, we are continuously updating our email security solution by creating a threat database containing an average of 10 new or variant APT attacks per day.”

LG CNS accelerates its security business with MS (Microsoft). Based on the collaboration with MS, we will pursue the following: △Design of generative AI security architecture2) △Development of customer-tailored detection and response platform △Strengthening of cloud security business, etc.

In particular, we design and build a security architecture for generative AI such as ChatGPT based on the MS Azure OpenAI Service3).

LG CNS is a solution provider for companies that want to utilize generative AI but are hesitant due to data leaks. It analyzes the customer's business environment and IT system to define the elements that require security, designs and builds an architecture to provide a customized security environment. Through this, customers can obtain the information they need through generative AI and prevent personal information leaks.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김예지 기자
김예지 기자