AI/ICT

[Information Security Solutions Conference] “Public AI Expansion ... Building an N2SF Response Framework With AI-DLP”

IT DAILY ·

김주섭 윈스테크넷 클라우드전략사업실 이사가 ‘2026 정보보호 솔루션 컨퍼런스’에서 ‘안전한 AI 보안 체계를 기반으로 한 생성형 AI 활용 전략’을 주제로 발표를 진행했다. (사진: 성원영 기자)

✦ AI Summary

As generative AI spreads in the public sector, the need for a DLP framework specialized for generative AI is growing.

Kim Ju-seop of Wins Technet presented five threats alongside the growing use of AI in the public sector, including sensitive information input and leakage, information leakage via attachments, unauthorized AI services, training data extraction, and prompt injection.

He said input and output data logging and monitoring, as well as DLP specialized for the AI environment, are necessary, and identified prompt security, coding assistant security, MCP security and network-based security as core elements of AI-DLP.

As generative AI spreads in the public sector, the need for a DLP framework specialized for generative AI is growing, it was noted. DLP, a data protection security technology within organizations, is drawing attention for its ability to detect critical and sensitive information and block or control external leaks.

Against this backdrop, Kim Ju-seop, director of Cloud Strategy Business at Wins Technet, gave a presentation on the 9th at the EL Tower in Yangjae-dong, Seoul, at the "2026 Information Security Solutions Conference." The theme of Kim Ju-seop's presentation was "Strategies for Utilizing Generative AI Based on a Safe AI Security Framework."

Kim Ju-seop explained security threats arising from the spread of generative AI adoption in the public sector and presented response measures. The event was reported by IT Daily, and the photo was taken by Seong Won-young.

AI use in the public sector has surged recently. Of 343 public institutions, 132 had carried out 381 cases of AI utilization and government service development. Kim said AI use in the public sector is increasing.

As public institutions increase AI adoption and service development, the need to manage security threats has also come into focus. Kim presented five major AI system threats: sensitive information input and leakage, information leakage via attachments, use of unauthorized AI services, training data extraction, and prompt injection, which involves malicious instructions directed at AI.

The National Intelligence Service (NIS) considered security threats in the process of using generative AI. The National Intelligence Service (NIS) also presented the need for essential management targets and controls.

Meanwhile, under the National Network Security Framework (N2SF) unveiled last year, each institution must identify and apply work information and information systems. Differential security controls by C, S and O grades must be applied based on the importance of the work, and for this, work classification must come first. Defining security equipment for control by each grade is also a prerequisite for differential security application by grade.

Kim emphasized logging and monitoring of input and output data as a response to the major AI system security threats identified by the NIS. He also said there is a need to introduce DLP specialized for the generative AI environment. He explained that the purpose of adoption is to secure visibility into data passing through AI and to control data leakage.

He then said the N2SF information service model in the N2SF guidelines consists of 11 components in total, and among them selected three models with high public sector relevance: No. 2, "Using generative AI in a work environment," No. 4, "Internet use for work terminals," and No. 8, "Cloud-based integrated document system."

Kim pointed out that in a generative AI environment, existing pattern- and signature-based security alone is insufficient. He also explained that a separate approach is needed, along with alternatives, to respond to threats in architectures that use large language models (LLM) and graphics processing units (GPU).

Kim presented prompt security, coding assistant security, model context protocol (MCP) security, and network-based security as the core elements of an AI-DLP solution. He explained that AI-DLP solutions should protect user input, code operations, AI-server communications, and network segments.

Regarding the need for prompt security, Kim said that in the process of questions, instructions and expressions entered into generative AI, sensitive information must be prevented from entering and risky forms of transmission must be controlled. On the need for coding assistant security, he explained that management is needed to prevent the input of security-problematic information during code generation and modification, and to prevent exposure of the results.

Regarding the need for MCP security, Kim said that it must be possible to block inappropriate data transmission in MCP-based AI-server communication flows. He then said that for network-based security, SSL inspection must be included because it is difficult to cover with the scope of existing security products.

Kim explained that even in encrypted segments, leakage possibilities must be checked and controlled. SSL inspection is a security technology that decrypts encrypted network communications such as HTTPS in the middle, inspects internal data, and then re-encrypts it before forwarding.

Kim said there is a need to block unauthorized transmission to external AI, to fundamentally block the exposure of sensitive data, and to have data control measures by context as well as data control measures by attachment classification. He added that implementing this requires visibility through AI-DLP and transparency through AI-DLP, and that because the task is difficult for an institution to handle alone, it is necessary to build a collaboration system with experienced vendors. He also said that if such a collaboration system is established, it would be a good opportunity to prepare for next year's business.

Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=241497

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.