Akamai: Patch-First Response Is Already Too Late... Security Framework Must Assume Intrusion
TECHWORLD ·
✦ AI Summary
Akamai said that as AI speeds up attacks, patch-centric responses alone are already too late.
It said a security strategy that assumes intrusion, immediate isolation after intrusion, and blocking attack spread are necessary.
It presented a multilayer security framework, including microsegmentation, browser security, and API security.
In the security industry, there is a growing view that what is needed is a security framework focused not on blocking intrusions, but on minimizing damage after an intrusion. That is because AI is accelerating attack speeds, exposing the limits of patch-centric responses.
Akamai expressed the same view. The company said enterprises need to establish a security strategy that assumes intrusion, on the premise that responses relying only on patch preparation and deployment are already too late.
Akamai Korea held a media briefing on the 22nd. The session introduced changes in security threats in the AI era and response strategies.
Akamai said the security ecosystem is changing rapidly since the emergence of AI. It also said machine-speed intrusion attacks are spreading.
Akamai said the limits of responses based on patch preparation and deployment have been reached. Accordingly, it said the response direction should shift from completely blocking intrusions to preventing attacks from spreading to other assets after an intrusion, and that a system for immediate isolation after intrusion is needed for that purpose.
Han Jun-hyung, managing director at Akamai, said that preemptive patching is already too late in terms of response timing, and that companies' security plans should be designed on the assumption that assets have already been compromised. He added that when an impact occurs, damage must be minimized as much as possible, and that immediate isolation should be introduced for that purpose. He said the purpose of immediate isolation is to reduce the scope of damage.
Han said that as the use of AI expands, the attack surface has widened to internal assets, browsers, and APIs. Accordingly, he said companies should consider a multilayered security framework that protects each area. He identified microsegmentation, browser security, and API security as key security elements in the AI era.
In particular, Han emphasized the importance of immediate isolation based on microsegmentation. He explained that the microsegmentation approach assigns attribute labels to each enterprise asset and uses those labels as a benchmark to closely identify and control communication between assets.
He also said that when a specific area is compromised, attacks can be prevented from spreading to other assets. He explained that this can minimize damage by stopping the spread of attacks.
He explained that browsers are a major point of contact for using generative AI at work, which makes browser security highly important. He said organizations must block external data leaks routed through unauthorized AI tools and overly permissive extensions, and that to do so, they need to identify and control the tools and extensions used in the browser environment.
He then explained that APIs can be attacked by exploiting flaws in business logic and authentication structures, even when they appear to be ordinary communication between devices. For this reason, he said API security requires more than simply checking whether communication is legitimate, and that it is necessary to understand the actual behavior and vulnerabilities of the API environment.
The speaker said this is why a phased security framework is needed. He stressed that building a multilayer security framework can prevent internal critical assets from being leaked outside and can also block external threats from entering the internal network through vulnerabilities.
The speaker explained that various attack types cannot all be eliminated with a single defense system, and emphasized the need for multi-layered defense as an alternative.
Akamai said it provides major security solutions and presented tools suited to this purpose: 'WorkForce Protector' controls endpoint-browser interactions, 'Guardicore Segmentation' isolates infrastructure workloads and blocks lateral movement by attackers, and 'API Security' protects machine-to-machine communication and secures RAG data flows.
Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407289
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.