AI/ICT

WiseStone Holds In-House Tech Seminar

IT DAILY ·

와이즈스톤은 최근 본사 연구원들의 기술적 통찰력을 높이고 품질 검증 역량을 고도화하기 위한 ‘사내 테크 세미나’를 개최했다.

✦ AI Summary

WiseStone held an in-house tech seminar at its headquarters.

The topic was cybersecurity, integrity, and authenticity verification, and Assistant Researcher Park Seong-hyeok delivered the presentation.

The seminar explained that integrity and authenticity are a core foundation, and that flexible judgment is needed by asset type, threat level, and application environment.

WiseStone recently held an in-house tech seminar at its headquarters. The event was aimed at improving the technical insight of headquarters researchers and advancing their quality verification capabilities.

The theme of the seminar was cybersecurity, integrity, and authenticity verification. The presentation was delivered by Assistant Researcher Park Seong-hyeok. Park explained that in practice, there is often a misunderstanding that encryption, or confidentiality, alone can prevent tampering, or ensure integrity.

Park said a clear understanding of data-change detection and provenance verification technologies is necessary, and that such understanding is the starting point for testing. He also explained in the presentation that simple data inspection methods can detect accidental communication errors, but have limitations when it comes to responding to deliberate manipulation by attackers.

He then noted that effective protection against tampering requires considerations tailored to each operating environment. The environments cited for consideration were resource-rich server environments and highly constrained embedded and IoT device environments.

At the seminar, "authenticity" was not treated as a single fixed technology, but as an area for exploring customized approaches by subject and environment, in terms of verifying the topic, data, communication counterpart, and legitimate source. As part of discussions on multi-faceted and systematic measures to secure authenticity, technical insights for practical application were also shared.

To that end, the seminar reviewed the introduction of lightweight security algorithms while basing the approach on public-key cryptography and authentication systems, taking into account device computation and storage burdens. It also examined authentication for network communication segments to block spoofing attacks, and continued the discussion with measures to enforce execution of only approved software during device startup, as well as verification of executable code.

A WiseStone official said the seminar content was not meant to declare an absolute answer for any particular security technology. The official then stressed that flexible judgment is needed to determine the optimal approach by asset type, threat level, and application environment. The official also described the event as a place to share practical insights.

The speaker said that integrity and authenticity in security are not flashy technologies, but a core foundation, and that if this foundation collapses, all higher-level security functions cannot be trusted. The speaker added that the company plans to continue holding practical in-house tech seminars, and said it intends to use them to internalize employee expertise and then provide a higher level of safe testing services for clients.

Source: IT DAILY · Kim Ho
Original: https://www.itdaily.kr/news/articleView.html?idxno=241676

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.