This page was machine-translated and may differ from the original. View original
[Discussion] The Core of the Much-Debated IoT Security: Hardware or Software?
If a product requires security, you must plan from the design stage to lower the price.
Reluctance to share data will make crisis prediction (Thread report) difficult
Experts discussed IoT security at the Samsung Security Tech Forum (SSTF) hosted by Samsung Electronics.
An IoT security industry professional voiced the limitations. While applying hardware based on academic opinions that hardware security is robust is expensive, software offers low performance. Consequently, the industry's stance is that they have no choice but to adopt software that can meet the price point, even if it means lower performance.
How should we view investments in contentious security?
Professor Baek Yun-heung of Seoul National University
The determining factor for hardware pricing is mass production. Mass production lowers prices. We must develop universally applicable IoT and find a way to standardize it. We need to consider not only performance but also services.
Professor Kim Yong-dae of KAIST
It is a misconception that companies view security as a separate solution. Incorporating security into the design phase lowers the cost. Adding it later, after the design is complete, increases the expense. If a product requires security, it is crucial to include it during the design phase. Just look at Kakao Bank; security and usability improve together. It is a loss if you do not secure it now.

How to Evaluate the Security of IoT Devices with a Wide Range of Issues
Executive Vice President Giljun Ahn, Head of Security Team at Samsung Electronics Software Center (Chairperson)
As the range of IoT devices is so wide that existing requirements cannot be met, the European Union (EU) announced it would release standards, while the U.S. stated that Consumer Reports would release labels.
What kind of movements are taking place domestically?
Professor Kim Yong-dae of KAIST
It is difficult to evaluate hardware because its source code is not disclosed. When new equipment is released, researchers evaluate its security. It is still too early to assess product safety.
Professor Kim Hyung-sik of Sungkyunkwan University
Standards organizations will each create their own test criteria. I am skeptical whether they can guarantee product security, but they can be created based on checklists. I read the security evaluation report published by KISA (Korea Internet & Security Agency). I believe it is appropriate for the government to share examples and research what kind of warnings to issue to companies that do not adhere to security protocols, rather than intervening technically.
Issue: Has security become intelligent in the era of the Fourth Industrial Revolution?
Executive Vice President Giljun Ahn, Head of Security Team at Samsung Electronics Software Center (Chairperson)
With big data and artificial intelligence gaining attention in the Fourth Industrial Revolution, 'Thread Report,' which predicts and responds to crises, is being mentioned as a key term in security.
How prepared do you think we are for this kind of intelligence?
Professor Kim Yong-dae of KAIST
To predict crises, one needs a lot of information, but even when new types of malware emerge overseas, it takes a long time for them to reach Korea. I am not sure how to improve this. It seems to be because we do not have a culture of paying for information. In the U.S., the military and government work together, but in our country, isn't the private sector providing data out of necessity?
Raon Security CEO Yang Jeong-gyu
“We talk about the sharing spirit of hacking groups, but sharing does not take place even within the groups themselves. Since collecting data itself is difficult, efficient sharing is also challenging. To collect data, one must install honeypots on overseas servers or distribute user nodes, which is practically difficult. To solve this, we must first create an organization capable of sharing, but the outlook is not bright as it does not seem likely to happen domestically.”
In addition , the importance of training experts to address the security challenges facing artificial intelligence and big data was also mentioned.
Professor Baek Yun-heung of Seoul National University
It is difficult to sift through massive amounts of data to extract the information necessary for security. It is a situation where rules do not apply to machine learning. We need to use artificial intelligence to detect attacks that bypass the rules, but AI lacks the critical insights. The training of experts is necessary.
Reluctance to share data will make crisis prediction (Thread report) difficult
Experts discussed IoT security at the Samsung Security Tech Forum (SSTF) hosted by Samsung Electronics.
An IoT security industry professional voiced the limitations. While applying hardware based on academic opinions that hardware security is robust is expensive, software offers low performance. Consequently, the industry's stance is that they have no choice but to adopt software that can meet the price point, even if it means lower performance.
How should we view investments in contentious security?
Professor Baek Yun-heung of Seoul National University
The determining factor for hardware pricing is mass production. Mass production lowers prices. We must develop universally applicable IoT and find a way to standardize it. We need to consider not only performance but also services.
Professor Kim Yong-dae of KAIST
It is a misconception that companies view security as a separate solution. Incorporating security into the design phase lowers the cost. Adding it later, after the design is complete, increases the expense. If a product requires security, it is crucial to include it during the design phase. Just look at Kakao Bank; security and usability improve together. It is a loss if you do not secure it now.
How to Evaluate the Security of IoT Devices with a Wide Range of Issues
Executive Vice President Giljun Ahn, Head of Security Team at Samsung Electronics Software Center (Chairperson)
As the range of IoT devices is so wide that existing requirements cannot be met, the European Union (EU) announced it would release standards, while the U.S. stated that Consumer Reports would release labels.
What kind of movements are taking place domestically?
Professor Kim Yong-dae of KAIST
It is difficult to evaluate hardware because its source code is not disclosed. When new equipment is released, researchers evaluate its security. It is still too early to assess product safety.
Professor Kim Hyung-sik of Sungkyunkwan University
Standards organizations will each create their own test criteria. I am skeptical whether they can guarantee product security, but they can be created based on checklists. I read the security evaluation report published by KISA (Korea Internet & Security Agency). I believe it is appropriate for the government to share examples and research what kind of warnings to issue to companies that do not adhere to security protocols, rather than intervening technically.
Issue: Has security become intelligent in the era of the Fourth Industrial Revolution?
Executive Vice President Giljun Ahn, Head of Security Team at Samsung Electronics Software Center (Chairperson)
With big data and artificial intelligence gaining attention in the Fourth Industrial Revolution, 'Thread Report,' which predicts and responds to crises, is being mentioned as a key term in security.
How prepared do you think we are for this kind of intelligence?
Professor Kim Yong-dae of KAIST
To predict crises, one needs a lot of information, but even when new types of malware emerge overseas, it takes a long time for them to reach Korea. I am not sure how to improve this. It seems to be because we do not have a culture of paying for information. In the U.S., the military and government work together, but in our country, isn't the private sector providing data out of necessity?
Raon Security CEO Yang Jeong-gyu
“We talk about the sharing spirit of hacking groups, but sharing does not take place even within the groups themselves. Since collecting data itself is difficult, efficient sharing is also challenging. To collect data, one must install honeypots on overseas servers or distribute user nodes, which is practically difficult. To solve this, we must first create an organization capable of sharing, but the outlook is not bright as it does not seem likely to happen domestically.”
In addition , the importance of training experts to address the security challenges facing artificial intelligence and big data was also mentioned.
Professor Baek Yun-heung of Seoul National University
It is difficult to sift through massive amounts of data to extract the information necessary for security. It is a situation where rules do not apply to machine learning. We need to use artificial intelligence to detect attacks that bypass the rules, but AI lacks the critical insights. The training of experts is necessary.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















