Insight

[Case Study] Korea Forest Cooperative Federation Establishes AI-Based Preemptive Security Response System

IT DAILY ·

View of the headquarters of the National Forestry Cooperative Federation on Seokchonhosu-ro in Songpa-gu, Seoul [Photo: National Forestry Cooperative Federation]

✦ AI Summary

The Korea Forest Cooperative Federation built a monitoring system that combines AI analytics and security operations automation. It integrated data from mutual finance and forestry support operations to refine its anomaly analysis framework and establish a framework linking analysis results to response actions. By applying Igloo Corporation's SPiDER ExD and SPiDER SOAR, it improved log analysis efficiency and shortened response time after threat detection.

The Korea Forest Cooperative Federation has built a monitoring system that combines AI analytics and security operations automation. It integrated the target data generated in mutual finance and forestry support operations and refined its anomaly analysis framework based on the unified data. It also established a framework that links analysis results to response actions.

Through this overhaul, the federation improved log analysis efficiency and shortened the time needed to respond after threat detection. In the process, the federation's security team defined the problems in monitoring operations and the procedures needed, and pushed ahead with enhancements.

The project result came from cooperation between the Korea Forest Cooperative Federation and Igloo Corporation. Igloo Corporation provided the XDR platform 'SPiDER ExD' and the SOAR solution 'SPiDER SOAR,' and the application of the two solutions improved system completeness.

Founded in 1962, the Korea Forest Cooperative Federation is a specialized organization that contributes to national afforestation and forest management. It supports forest cooperatives nationwide and handles forest disaster prevention and recovery as well as mutual finance. The federation carries out both public-sector work and financial business within a single organization.

The federation's public-sector work is tied to enhancing the public value of forests, while its financial business involves handling cooperative members' assets. Accordingly, the protected assets vary widely, ranging from members' financial information and personal data to forestry project-related work systems.

Because it needed to protect financial information, personal data, and work systems at the same time, the federation has long been pushing ahead with stronger security capabilities. As digital transformation has advanced across the forestry and financial sectors, information protection has become the foundation supporting the federation's services.

At the same time, cyber threats have grown faster and stronger, security operations requirements have risen, and the scope of protection has expanded. The increase in system and device data has also made it more important to precisely identify signs in large volumes of information that may indicate real threats.

As data volumes increased, the federation saw limitations in its existing security monitoring and pushed ahead with modernizing its security framework. The existing approach required checking events from different devices one by one, making it difficult to understand relationships among attacks. As a result, it was hard to grasp the overall context, and log search and analysis took a great deal of time. Even after a threat was discovered, multiple levels of personnel confirmation were needed before actual response actions could begin.

After diagnosing these problems, the federation began design work and partnered with Igloo Corporation. The federation's IT Strategy Division information security team focused on a system that connects data flows to detect anomalies.

The direction set by the federation was to shift from post-incident response to proactive security operations. The goal was to strengthen the ability to identify risks in advance rather than placing the emphasis on confirming and addressing problems after they occur.

The first stage was an internal diagnosis. The federation reviewed items to identify time-consuming tasks and items to identify threats that actually lead to problems in its IT environment. Based on the diagnosis results, it then established the blueprint for the target security framework.

Based on the diagnosis results, the federation focused on building a real-time analysis system in a single environment for security data. The analysis scope covered public and financial operations as a whole. The federation envisioned the functions needed on site and designed detection policies and dashboards. It also organized the response procedures after a threat is discovered, item by item, in the order of action and approval.

Based on these design functions and policies, the federation selected Igloo Corporation's XDR platform 'SPiDER ExD.' It also selected the operations and threat automation solution 'SPiDER SOAR' based on the same design functions and policies. 'SPiDER ExD' offered high-capacity log search and analysis performance and could connect data generated across multiple devices, meeting the federation's needs. It also provided dashboards and correlation analysis screens that could be configured by task, and those task-specific dashboards and correlation analysis screens were key selection points.

'SPiDER SOAR' made it possible to configure task-specific Playbooks for the operating environment and supported the creation of automated response scenarios. The federation viewed this as a factor that would reduce operational burden. It also saw value in the ability to speed up threat response.

This article is about an interview with Yoon Seop-yeob, head of the Information Security Team in the IT Strategy Division at the Korea Forest Cooperative Federation, regarding Igloo Corporation's XDR platform 'SPiDER ExD(SPiDER ExD).' Photo courtesy of Igloo Corporation.

Yoon Seop-yeob first pointed to time pressure as a problem with existing security work. He explained that the combination of larger system scale, increasing threats, and more events to verify made it difficult to respond using the existing method.

In particular, he said the organization could not handle the situation with its per-event verification method. Log search and analysis took a long time, and the need to check events separately by device also added to the burden, he said.

He also explained that it was difficult to understand the relationships and context of attacks amid large volumes of information. He said that even after a threat was discovered, multiple levels of confirmation from responsible staff were required before analysis and action, causing delays.

As the person in charge of practical operations, Yoon Seop-yeob was responsible for analyzing the problems with the existing security monitoring system. He said the project involved designing detection policies tailored to the organization to reduce these problems.

He also designed correlation analysis rules and dashboards. He explained that he was also responsible for designing SOAR Playbooks and approval procedures.

He said the team avoided simply applying the product's default functions. Instead, it proceeded with the design based on actual incident response experience.

Yoon Seop-yeob explained that the team first focused on specifying the threats to detect. He added that it also worked to define the procedures that link analysis and action after detection.

In the process of applying the prepared plan to the operating environment, the team focused on internal information leaks and unauthorized access. It judged these types to be the ones most likely to cause major damage if response was delayed, so it established detection scenarios centered on them. It also organized the response methods and approval authorities when a threat is confirmed as Playbook content.

The process of building this framework was not easy. There was the task of organizing different log formats by device into a single standard, and there was also the task of specifying correlation analysis rules that reflect the workflow. Igloo Corporation actively supported the build process and also collaborated to improve the design into a form that could be implemented in practice.

As a result, the federation established a framework suited to the business scope and operating environment. Looking ahead, there is a state in which areas where automation has been applied and areas where it has not yet been applied coexist. Accordingly, the federation set a plan to reflect response cases accumulated during operations in the Playbooks.

It also plans to expand the scope of automation. Generative AI-based threat investigation and interpretation functions are currently in pilot operation, and the federation plans to verify the functions in real work and improve their practical use. Through this, it aims to accurately separate human judgment tasks from technical processing tasks and improve security operations.

The federation began cooperation with Igloo Corporation and started the work of realizing the design. The federation and Igloo Corporation completed Playbooks and response and approval procedures by reflecting threat intelligence and past cases. They also prepared internal information leak detection scenarios, unauthorized access detection scenarios, and abnormal behavior detection scenarios, considering the possibility of major damage if response is delayed, and they refined correlation analysis policies suited to the organization's work environment and threat characteristics.

After that, the federation and Igloo Corporation carried out the migration of existing operating policies to the new environment. In this process, the federation's working-level staff and Igloo Corporation engineers held discussions and normalized different log formats by device into a single standard. They also established normalization criteria and correlation analysis rules suitable for the workflow.

This completed an analysis environment that connects scattered security data. It secured threat visibility based on the relationships among multiple security data sources, and even events that appear normal on a single security device can now be identified as anomalies and potential threats when multiple data sources are linked. As a result, the federation moved away from separately checking individual events, and the threat detection capabilities of the federation and Igloo Corporation were also strengthened.

The federation expanded the monitoring scope. The expanded scope included externally introduced threats, as well as abnormal behavior on user PCs and compliance with internal security policies.

The federation has an integrated analysis environment, and it combined that with AI and automation technologies. Rather than focusing simply on expanding threat detection, it focused on quickly sorting out real threats from among many events and linking analysis results to actual response actions.

To do this, the federation linked SPiDER ExD on top of its existing correlation analysis policies. Using the functions provided by SPiDER ExD, it enabled AI-based threat detection and analysis, and the implementation included support for determining false positives and true positives as well as support for threat analysis.

AI was responsible for analyzing event characteristics and related information and for identifying and guiding threats that required urgent response. As a result, staff spent less time checking repetitive events and could focus on high-risk threats.

The federation also applied a pilot version of a threat investigation and interpretation function using generative AI. The function supports rapid search of alerts and logs and the combination of events and data to help understand threat content and context, and it provides response directions and vulnerability-check information based on analysis results. This improved the overall speed of investigation, from threat search and interpretation to follow-up judgment.

As the federation's response methods and approval procedures were moved into the automation framework, it built automated scenarios reflecting the federation's designed Playbooks and automated scenarios reflecting the federation's designed response and approval procedures. Accordingly, it established a structure in which analysis is performed automatically when anomalies are detected and a structure in which action is automatically linked when anomalies are detected. SPiDER SOAR was presented as the response entity after analysis.

In this process, the sections that depended on manual human work were minimized. Because internal information leaks and unauthorized access can lead directly to damage if response is delayed, analysis and action now proceed with reduced human intervention once anomalies are found.

The federation announced that large-volume log search and analysis performance improved this time. Log analysis efficiency increased by 60% compared with before, and the average time from threat detection to response was shortened by 90% compared with before.

As a result of the project, the federation introduced integrated data analysis, connected AI-based threat identification, linked automated response through SOAR, and built a structure for early anomaly recognition and response. Accordingly, the center of security operations shifted from 'post-incident response' to 'proactive response,' and the future goal was presented as an 'autonomous SOC.'

In security operations, the roles of security staff changed as the solution took over repetitive event checks and standard response procedures. As a result, the role of security personnel was restructured to focus on analyzing and judging complex, high-risk events.

This change led to a method that combines the organization's experience and practitioners' ideas with the solution, and as a result, an intelligent security operations framework based on understanding signs and context was established. Based on this, the federation is aiming for an autonomous SOC and first established automation for detection, analysis, and response.

As a follow-up plan, the federation is pushing ahead with a SOAR enhancement project and aims to expand the share of security monitoring automation. It plans to deploy AI agents in the SOC so they can autonomously carry out threat investigation, interpretation, and response tasks. Lee Hyeon-seung, head of the IT Strategy Division at the Korea Forest Cooperative Federation, said the federation plans to gradually expand the share of security monitoring automation through the SOAR enhancement project and aims for an autonomous AI security framework that can flexibly respond to changing cyber threats with three goals: maintaining business continuity, securing stability, and responding to regulations.

Lee Hyeon-seung, head of the IT Strategy Division at the Korea Forest Cooperative Federation, explained that the federation is responsible for supporting forest cooperatives and cooperative members nationwide and carries out public-interest operations such as mutual finance and forestry projects.

He said that in this process, the federation is in a situation where it must protect members' assets, personal data, and forestry project support systems together.

Lee Hyeon-seung said the federation judged that existing methods alone would make it difficult to ensure security that meets cooperative members' trust, as cyber threats become more sophisticated and the volume of security data continues to grow.

Accordingly, the federation recognized that it needed not just a simple system replacement but a shift in its security approach, and it pushed ahead with a project to build an AI-based preemptive security operations framework, he explained.

Lee Hyeon-seung said the federation pushed ahead with this project because it sees security capability as the foundation of cooperative members' trust, and that security is an area where results are not very visible.

He said the framework for this project was designed directly by the Information Security Team and pushed ahead in a way that let practitioners who know the organization's circumstances well design the policies, procedures, and functions.

Lee Hyeon-seung said the project is meaningful because it laid the foundation for autonomous improvement and flexible response to future environmental changes.

As a future plan, the federation is pushing ahead with a SOAR enhancement project. Through this, it plans to gradually expand the share of security monitoring automation and then implement an autonomous AI security framework that can respond to the changing security landscape.

The federation aims for an autonomous SOC by deploying AI agents inside the security operations center so they can understand context and situation and autonomously analyze and judge unknown patterns. The starting point for all these projects is the safe protection of the assets and information provided by cooperative members, and this duty of protection is both the federation's role and the reason it exists.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241863

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.