“The Essence of Security Does Not Change”...SK Shieldus Releases Shadow IT Security Threat Analysis and Response Guide
TECHWORLD ·
✦ AI Summary
SK Shieldus released the "Analysis and Response Guide for Incidents Targeting Shadow IT in the Era of AI-Automated Attacks." The guide analyzes Shadow IT and API security issues, as well as how AI-based attack tools are used and the actual intrusion paths, based on recent financial-sector incidents. SK Shieldus identified Shadow IT as the starting point of AI attacks and proposed asset identification, monitoring, detection and response, and zero-trust-based control.
SK Shieldus released the "Analysis and Response Guide for Incidents Targeting Shadow IT in the Era of AI-Automated Attacks." The guide examines the Shadow IT and API security issues that have emerged as major threats in the era of AI-automated attacks. SK Shieldus compiled the guide based on recent incident cases in the financial sector.
The guide includes an analysis of how AI-based attack tools are used, an analysis of actual intrusion paths, and a security framework for companies to prepare for similar attacks. Through this, SK Shieldus outlined the security issues that require attention in an AI-automated attack environment and the direction for response.
Based on a comprehensive review of publicly disclosed details, SK Shieldus determined that the incident was not an example of AI creating a new attack technique. It said the case was closer to the automation and sophistication of existing attacks, and that the essence of security does not change. The key point was not that AI created a completely new method, but that it enabled existing attacks against poorly managed external assets to be carried out faster and at larger scale.
The first targets attackers went after were externally exposed assets, not core financial transaction systems. Examples of externally exposed assets included loan broker systems, employee support services, and sales support platforms. These assets were characterized by blind spots in management, and analysis showed that AI played a role in searching for such externally exposed assets more quickly and at larger scale.
Using AI-based automated attack tools makes it possible to simultaneously scan internet-exposed assets and APIs across multiple financial institutions. It also allows attackers to rapidly expand targets based on API call patterns and response information. As major business operations are carried out in API-linked environments, AI can mimic normal call patterns and also conduct large-scale scanning and information gathering, raising the possibility of increased threats.
In connection with this, SK Shieldus's guide disclosed the operating principles and risks of ARTEX, an AI-based penetration testing tool. The guide also raised the possibility that ARTEX could be used for attack purposes.
EQST(Experts, Qualified Security Team), a white-hat hacker group, analyzed ARTEX directly. Based on that, EQST derived how autonomous AI-based attacks operate and their security implications.
ARTEX is an open-source autonomous penetration testing platform that automates the manual red-teaming process with AI. It differs from simple automated scanning tools. ARTEX can autonomously select the next target to examine based on prior results, and thereby expand the attack path.
Based on publicly available information and tool analysis results, SK Shieldus determined that the structure automated reconnaissance, vulnerability discovery, and verification processes carried out by attackers. As a result, it said attack speed and scope expanded significantly. It also said attackers may have used publicly available AI-based penetration testing tools and routed traffic through VPS servers rented in multiple countries to scan internet-exposed services and APIs across multiple financial firms.
SK Shieldus viewed this case not as AI creating a new attack technique, but as an example of automating and advancing existing attack processes. The actual attack was described as progressing through stages such as scanning externally exposed assets, checking weaknesses in authentication and authorization verification, mass queries, bypassing blocks, and spreading to other organizations.
SK Shieldus explained that AI's role in this process was to automate the attack workflow, and that the effect appeared as increased speed and scale. It also judged that this structure significantly expanded attack speed and scope by automating attackers' reconnaissance, vulnerability discovery, and verification processes.
SK Shieldus identified Shadow IT as the starting point of AI attacks. It explained Shadow IT as systems, services, and APIs operated outside the security team's management list and control scope.
SK Shieldus defined the scope of Shadow IT as including assets whose existence is unknown. It also said assets whose existence is known but that are deprioritized in management and therefore not sufficiently security-checked also fall under Shadow IT.
SK Shieldus then assessed the main attack path in this incident as externally exposed business-support systems and APIs rather than core financial transaction systems. Its view was that the path of attack in this case was not through the core financial transaction system, but through business-support systems and APIs exposed to the outside.
SK Shieldus explained that after attackers scan such assets, they may expand the scope of damage by repeatedly querying accessible information. In other words, once externally exposed assets are identified, repeated queries can lead to greater damage.
SK Shieldus said the latest result shows the essence of AI attacks. It added that the essence of AI attacks lies not in discovering new vulnerabilities, but in rapidly scanning and exploiting unmanaged assets.
Because APIs are the area where business logic and data access paths are concentrated, SK Shieldus said that if AI analyzes this area, the efficiency of mass queries could increase, the efficiency of attempts to bypass privileges could increase, and the efficiency of expanding abnormal calls could also increase.
Accordingly, the guide presented representative Shadow IT types in ordinary enterprise environments. These included neglected test servers, legacy web applications, outsourced operations systems, and integrated SaaS.
The guide also included measures for checking and managing Shadow IT. SK Shieldus emphasized securing asset visibility as the top priority for responding to AI-based automated attacks, and said that because AI can quickly scan internet-exposed APIs and vulnerable assets, companies need to accurately identify and manage the assets they own.
The guide also presented a three-step response framework for API security. The framework consists of Discovery, API Monitoring, and Detection & Response.
First, it is necessary to identify externally exposed assets from the attacker's perspective and eliminate Shadow IT. Next, it is necessary to continuously monitor the authentication and authorization systems of APIs in operation, and also continuously monitor API call activity in operation.
It is also necessary to link security frameworks such as WAF, EDR, NDR, and SIEM, and to detect and block abnormal behavior through those linked systems. In addition, behavior-based analysis centered on users, sessions, and access patterns rather than IP is needed, and such behavior-based analysis is necessary to counter AI-automated attacks.
At the same time, simply checking whether authentication exists is not enough; authorization verification for the requested data is needed. In addition, security standards for overall API operations need to be established.
SK Shieldus explained that protection is impossible if assets are not recognized, and invisible calls cannot be controlled. It added that monitoring targets can only be finalized after asset identification is completed, and that this requires establishing monitoring criteria. It also said that if monitoring targets and criteria are secured, an effective detection and response framework can be built.
SK Shieldus said that although AI-based attacks are spreading, the essence of security and the principles of response do not change. It added that to ensure the effectiveness of the three-step API security framework, integrated control based on zero trust must be implemented in parallel.
SK Shieldus stressed that protecting externally exposed assets and APIs is the starting point. It also said control over the entire zero-trust domain is necessary, listing users and Identity, devices and endpoints, networks, applications and workloads, data, and visibility, analytics, and automation as those domains.
Kim Byung-moo, head of SK Shieldus's Cyber Business Division and vice president, said that AI is not a technology that creates new vulnerabilities, but a tool that amplifies attacks. Vice President Kim said companies need to secure visibility into the assets they own and strengthen control over externally exposed areas including APIs, and that the essence of security does not change even in the AI era. He added that the company will continue to provide practical security services so customers can respond to the changing threat environment, and will continue supporting the building of zero-trust-based security frameworks.
Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407914
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.