Press Releases
Everspin CEO Young-bin Ha Speaks as a Key Presenter at 'Financial Innovation Security Forum 2024'
2024.05.01
Major cybersecurity companies participating in the 'Financial Innovation Security Forum 2024' agreed that as the information theft capabilities of hackers become increasingly sophisticated, cybersecurity levels must be upgraded accordingly. In March 2022, global companies like Samsung Electronics and NVIDIA suffered from hacking fears. This was because the international hacking group LAPSUS$ easily neutralized advanced security systems and unauthorizedly disclosed internal information. Hackers did not use difficult methods; they logged in using user accounts and passwords found on the dark web. User account information collected on the dark web by security venture Logpresso alone exceeds 128 billion cases. Logpresso CEO Bong-yeol Yang stated, "Hackers succeed in logging in within one or two attempts. It is difficult for existing security monitoring systems to find internal intruders impersonating legitimate users. We must detect abnormal signs by combining all behavioral logs and intelligence from networks, endpoints, and applications." CEO Yang further suggested, "As the government designates SaaS (Software as a Service) as an innovative financial service and allows selective exceptions to network separation regulations, we should include the audit logs of SaaS services in monitoring targets to detect attackers intruding through SaaS." Logpresso, along with partners like Terasys, builds security platforms that integrate and monitor dozens of security solutions across internal infrastructure (on-premise) and cloud domains like SaaS to detect and respond to external breaches and information leaks. Security technology using AI to collect tens of millions of normal apps from the global market in real-time was also introduced. When a suspicious app is discovered, it is compared with the collected normal apps to determine its maliciousness. Everspin CEO Young-bin Ha stated, "Existing blacklist-based security has limitations because it collects malicious apps after an accident occurs. White-list-based malicious app detection technology that allows for proactive prevention is more effective." He emphasized that monitoring user device patterns and preventing sudden changes to abnormal pattern devices can fundamentally prevent phishing. He noted that they have detected approximately 7.1 million malicious apps using this method over the past two years, and the number of detected identity theft devices recently reached about 10,000. CEO Ha added, "We develop phishing, hacking, and identity theft prevention software and are expanding into Japan and Indonesia as well as domestic financial institutions." Some companies are merging analog security methods with non-face-to-face financial transactions. They argue that in situations where criminal organizations try to send smishing (SMS phishing) messages, distribute malware, or neutralize biometric authentication, analog methods can be effective. ThinkAT CEO Seong-in Jeong pointed out, "The threat of voice phishing through personal info theft is rising in North Korea, China, and Southeast Asia. Using Automated Response Systems (ARS) for confirmation in mobile banking can almost entirely prevent damage." He also noted that the enforcement decree of the so-called 'Voice Phishing Prevention Act' passed by the National Assembly early this year would have limited effects if voice warnings aren't included in non-face-to-face transactions. The law requires financial institutions to take active measures like recording during transfer/remittance processes for suspected accounts. CEO Jeong said, "If a warning ARS call is made for transfers of over 1 million won across smartphones, PCs, or ATMs, a high security effect can be expected at a cost of about 1 won per second."
