Artificial intelligence has boosted human productivity, but it has also enhanced the efficiency of hackers. Attackers now use AI to scout target systems, identify vulnerabilities, and even craft attack codes. Tasks that once took skilled hackers a long time can now be completed in an instant.
The most significant change in cyber warfare is speed. Traditional methods of defense cannot keep up with this pace. If the sword has become faster, the shield must also be upgraded. This is why the Korea Internet & Security Agency (KISA) has introduced a 'Korean-style security-focused AI.'
Defenders are facing increasingly difficult circumstances as the number of vulnerabilities continues to surge. The Forum of Incident Response and Security Teams (FIRST) predicts that the number of Common Vulnerabilities and Exposures (CVE) to be disclosed this year will reach approximately 66,000. The pace of disclosures in the first half of the year exceeded initial forecasts by 46.3%, marking the largest number ever.
However, even if the number of vulnerabilities increases tenfold, it is not feasible to increase security personnel by the same amount. Fortunately, only a small fraction of the vulnerabilities are likely to be exploited in actual attacks. This leads to a shift in perspective: instead of asking, 'How many vulnerabilities are there?' the question should be, 'Which ones should we prioritize for defense?'
KISA's expectations for AI lie in this shift. Rather than competing to find the most vulnerabilities, the goal is to have AI identify the vulnerabilities that pose the greatest risk of exploitation and prioritize responses accordingly.
Since May, KISA has been using OpenAI's Government and Agency Trust-Based Access (GTAC) program to assess external public web pages and commercial and open-source software for critical infrastructure. This AI-driven analysis significantly reduces the time required for assessments, which could take weeks or even months, allowing KISA to alert companies about the most dangerous vulnerabilities and assist with patches.
However, a critical question remains: Can South Korea's cyber defense rely solely on foreign general-purpose AI?
Global AIs, including ChatGPT, are exceptional general models trained on vast amounts of data. However, South Korea's security environment has unique characteristics, such as a network separation system, the widespread use of Hangul (HWP) documents in both public and private sectors, and layered security systems like Digital Rights Management (DRM) and electronic financial security modules.
Geopolitical factors, such as cyber threats from North Korea, also play a role. More fundamentally, there is the issue of information sensitivity. It is not feasible to input the structure and vulnerability information of national infrastructure and corporate internal systems into foreign commercial AIs. No matter how intelligent an AI may be, it cannot expose the critical vulnerabilities of a nation or corporation.
KISA's solution is the 'Korean-style security-focused foundation model.' This does not mean competing with the world's best general-purpose AIs across all fields. Instead, the strategy is to develop specialized AIs that focus intensively on South Korea's data and environment within the realm of cybersecurity.
KISA Threat Response Policy Team Leader Kim Eun-sung aptly compares this to a genius who excels in all subjects versus an expert who deeply understands one field. The goal is not to create an AI that is good at everything, but one that is best equipped to understand and counter cyber attacks targeting South Korea.
If developed correctly, the applications of this AI will be vast. It can sift through numerous vulnerabilities to identify the most dangerous ones, analyze malware, and detect signs of impending attacks. It will also guide security personnel on which systems to prioritize. This AI will serve as a 'security advisor' alongside human operators.
However, the government does not need to create all security services directly. KISA's proposed direction emphasizes role-sharing. The government will develop a foundational model with basic security knowledge and make it publicly available, allowing security companies to build specialized services for various industries such as finance, telecommunications, manufacturing, and public sectors on top of it.
This design is crucial. The government should not compete with private AI companies. Instead, it should lay a common foundation, while competition should occur among private entities on that foundation. The government builds the highway, but it does not manufacture the cars that drive on it.
Once a reliable foundational model is established, security companies and startups will contribute their technologies and data, leading to a more diverse range of services. At that point, the Korean-style security AI will become a public infrastructure for the security industry rather than just a single product.
In the age of AI, the concept of security is also changing. In the past, the focus was on building high walls to prevent enemies from breaching them. However, as AI continuously refines its attack techniques, the goal of perfectly blocking every attack is becoming increasingly elusive.
Now, the ability to delay attacks as much as possible and quickly detect anomalies to alert administrators before damage spreads is what will determine success. The key is not perfect defense, but how quickly threats are identified and how swiftly responses are executed.
In this context, AI will take on a role that humans cannot manage due to its speed. It will continuously scan the endless data flowing through networks and software to detect suspicious activities. Humans will then decide which actions to take, and organizations will be responsible for the outcomes. The structure involves AI detecting threats, humans making judgments, and organizations bearing responsibility.
However, security AI itself could become a new target. Attacks aimed at corrupting the data it learns from, disrupting its judgments, or extracting system information will inevitably emerge. While enhancing security with AI, it is also essential to protect the AI itself. Thus, cyber warfare in the age of AI is not a battle of 'AI versus humans,' but rather a contest between attackers wielding AI and defenders equipped with AI.
South Korea possesses world-class digital infrastructure across sectors such as semiconductors, telecommunications, manufacturing, and digital government. With so much at stake, the potential losses from breaches are significant. In the age of AI, national competitiveness is not solely determined by the sophistication of AI technology.
Another aspect of competitiveness is how securely that AI and digital infrastructure can be utilized. Pursuing the general-purpose AIs of the U.S. or China is not the only path to AI sovereignty. Having an AI that understands the unique risks of our society and can protect the nation's critical systems is also a vital aspect of technological sovereignty.
We are now in an era where AI has become a weapon for attackers. South Korea needs its own 'AI shield' to protect itself. The Korean-style security-focused foundation model is a declaration of our intent to strengthen that shield ourselves.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.

