A lawmaker said at a parliamentary audit that network-segmentation rules that block adoption of artificial intelligence-based security systems should be improved after multiple hacking incidents hit the financial sector. Financial Services Commission Chairman Lee Eok-won said he agreed AI should be introduced into defence systems to respond to AI-powered cyber attacks and would review a phased plan to improve regulations.
At an audit of the Financial Services Commission by the National Assembly’s Political Affairs Committee on Oct. 8, Democratic Party lawmaker Park Min-kyu (박민규) stressed the need to analyse massive access logs and signs of anomalies in real time through AI-based security monitoring and respond pre-emptively.
Park said hacking incidents occurred at seven financial companies within a week starting with Shinhan Bank on Sept. 27 and the number of leaked personal data cases reached 68,000. He also raised a claim that the Financial Security Institute is provisionally considering the possibility that AI was used in the attack. He pointed to the fact that recent incidents occurred in the process of connecting to external networks, including a loan broker lookup page and a mobile work-support system for employees.
“What matters is how quickly we analyse and respond to the vast access logs and signs of anomalies that build up every day,” Park said, stressing the need to build an AI-based security monitoring system.
He said many AI security services are currently provided through internet-based cloud systems, but financial companies face restrictions on using them on internal computer networks due to network-segmentation rules.
“The weapons hackers use become more advanced every day, but security-purpose AI, which is the defence system banks can use, cannot be used due to network-segmentation rules,” he said, urging institutional improvements.
He also raised issues with how an ongoing pilot project to use AI for security is being run. He said limiting the permitted test period to 1 year would make it difficult to encourage long-term investment at a time when financial companies have to spend significant costs to build AI security systems.
“How can financial companies invest actively when they do not know whether they can keep using it after 1 year,” Park said. “The test period for security AI should be sufficiently guaranteed to encourage participation by financial companies and long-term security investment,” he said.
Lee said he agreed with the intent. “To stop AI, in the end we have no choice but to use AI,” he said. “We are looking at various phased and effective ways to change network-segmentation rules,” he said.
◆ Proposal also raised for shared AI security system for smaller financial firms
The gap in security capabilities between major banks and smaller financial companies was also mentioned.
Park said the average number of dedicated security personnel at the four major banks is 92, while savings banks average 6, stressing the need to strengthen smaller financial firms’ ability to respond to security threats.
He also noted that in the recent wave of hacking incidents, the scale of personal data leakage at Yegaram Savings Bank was the largest. He said the approach of smaller financial companies building security systems individually has limits.
As an alternative, he suggested building a joint AI security system that several smaller financial companies could use together.
“The more vulnerable a smaller financial company is, the more it needs to pool scale and concentrate security capabilities and safety management,” Park said. “It could also be an alternative for the Financial Services Commission to support a joint security AI system in which several small and mid-sized financial companies participate together,” he said.
Park also cited cases of AI security use by overseas financial authorities. He said the United States and Europe are also strengthening responses to cyber threats using AI and called on the domestic financial sector to actively move to upgrade defence systems.
Lee said, “Thank you for the many good comments,” and added, “We will look into it.”
Click Here For The Original Source
