인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Cybersecurity is also a battlefield; domestically, there is no information sharing among relevant agencies.

Google 우선 소스Published2017.10.10 06:25
8 to 9 out of 10 cybersecurity cases are related to North Korea
The public bears the brunt of the conflict between related agencies; 'information exchange' is the solution.

According to announcements from various agencies, the number of people engaged in hacking in North Korea reaches 6,800. Relevant domestic organizations include KISA, the National Intelligence Service (NIS), and the Financial Services Commission (FSC). At a forum hosted by National Assembly member Yoo Seung-hee, the serious state of North Korea's cyber security was discussed.

The National Police Agency's Cyber Security Bureau tracked the activities of North Korean employees who hacked domestic systems by accessing North Korean IP addresses. Chief Investigator Jeong Seok-hwa stated, "Their work was identical to that of government officials." They arrived at work in the morning, clipped news articles, and collected information. They then sent malicious and phishing emails impersonating government officials. They primarily used portal site accounts and showed a trend of steadily increasing the frequency of email sending.

Photo source: Cisco

Initially, this was carried out primarily by government agencies, but recently it has spread to public and private entities as well. This includes the personal information hacking cases involving SK and Hanjin, the Interpark Bitcoin demand case, and the ATM electronic financial transaction information theft incident in September. The objective of the attack itself is money.

It has also been pointed out that due to the nature of the cyber security ecosystem, the scale of damage is greater than that of natural disasters, yet immediate recovery is not taking place.

Colonel Kim Han-sung of the Cyber Command also stated that while the United States accepts cyber as a battlefield domain and is preparing for it just like the land, sea, and air domains, the domestic response is inadequate.
He continued by warning, “There was a request to ‘provide the current status of state attacks,’ but the scope of action available to the Cyber Command is determined by whether the North Korean attack targets banks or virtual currency,” adding that the damage caused by the mixing of state agencies ultimately lies with the lives and assets of the people.

Domestic security has also advanced since 2009 as the police, the National Intelligence Service, and other related agencies have each experienced security incidents. However, because the Financial Services Commission, which is responsible for investigations, and private companies have different objectives, there are limitations in recovery and prevention of recurrence. This results in a situation where, even if the cause of a breach is identified, it remains unknown who committed the breach.

Jeong Seok-hwa, Head of the Investigation Division at the Cyber Terrorism Response Center, is speaking.

Chief Secretary Jeong said, “Only connections with each agency remain. How to connect them is important,” citing the U.S. National Council of Homeland Security (NCCIC), which changed after the 9/11 attacks, as an example.

In the United States, the Cyber Security and Communications Integration Center works together and naturally shares information. Although there are information sharing systems among the Ministry of Science and ICT, the National Intelligence Service, the Ministry of National Defense, investigative agencies, and military investigative agencies, information sharing carried out through systems has limitations. For real-time or sensitive information to be exchanged, they must be in the same space (platform).
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
김자영 기자