Dream Security:
IT DAILY ·
✦ AI Summary
In the financial sector, breaches at 7 financial companies occurred in succession, and the Korea Financial Security Institute also announced that it had detected attempts to attack using AI agents.
Financial authorities identified systems used by outside personnel and company employees, especially business support services exposed to the internet, as both the cause and target of the attacks.
Dream Security proposed a response combining FIDO2-based biometric authentication and zero-trust access control, and introduced Magic FIDO and Magic ICAM.
With a series of breaches in the financial sector and attempted attacks based on AI agents being confirmed, the need for account protection and access control is coming into focus. Since the end of last month, breaches have occurred in succession at 7 financial companies, including banks, savings banks, and capital companies. The Korea Financial Security Institute also announced that it had detected attempts to attack the financial sector using AI agents.
Financial authorities pointed to systems used by outside personnel, such as loan brokers and subcontractors, as well as company employees, as the cause of the breaches. In particular, the attacker is believed to have targeted business support services exposed to the internet. The attack method involved bypassing authentication procedures and then checking information.
Dream Security announced on the 7th that it had proposed a plan combining FIDO2-based biometric authentication and zero-trust access control. The purpose of this proposal is to respond to the growing threat of account theft.
Dream Security said it analyzed the incident as an example that shows the limits of network-separation-centered security. It said that in the process of pursuing AX, service integration is expanding through cloud, open API, and software as a service (SaaS). As a result, it explained, external points of contact on internal networks are also increasing.
Dream Security explained that information can be leaked even in a network-segregated environment if authentication and authorization do not work properly. Under the judgment that network separation alone is not enough in an environment where external integration is increasing due to AX, it presented a response measure that combines FIDO2 biometric authentication and zero trust.
The company's first measure is passwordless FIDO2-based biometric authentication. The storage location for the private key and biometric data is limited to the device. Accordingly, if a server is breached, the risk of leaking reusable authentication information can be reduced. In addition, because the structure makes password theft and credential stuffing impossible, the risk of credential stuffing is also reduced.
Dream Security supplies 'Magic FIDO' as a product that implements this. 'Magic FIDO' supports FIDO v1.0 and FIDO2. It has also obtained FIDO Alliance certification and GS certification.
The second measure is to establish a zero-trust-based access control system. Dream Security's solution for this is the identity authentication and authorization management 'Magic ICAM.' 'Magic ICAM' centrally manages the identity, credentials, and privileges of access subjects, providing service unification and automation functions.
'Magic ICAM' supports the implementation of MFA policies by situation and by user. It also supports interoperability among various security services and information systems based on linkage with API Gateway.
Oh Seok-ju, CEO of Dream Security, said that on the premise that it is difficult to eliminate all vulnerabilities in advance, basic security such as authentication should be reexamined as an alternative. He added that Dream Security plans to support the financial sector and public institutions based on Magic FIDO and help them transition to a safe and convenient Passwordless environment.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=242070
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.