Telecom

SKT and Upstage Launch AI Cybersecurity Consortium to Strengthen In-House AI Security Capabilities

IT DAILY ·

Attendees pose for a commemorative photo at the launch ceremony of the "Reader AI Cybersecurity Council." [Photo: SKT]

✦ AI Summary

SK Telecom has launched a joint independent AI cybersecurity consortium with Upstage, major domestic information security companies, and universities. The consortium has 11 participating organizations and was formed based on the collaborative ties established during the government's call for projects to develop a cybersecurity-focused AI foundation model. The consortium plans to train A.X K and Upstage Solar on field data from security companies, have universities verify safety, and then apply them to participating companies' security products and services.

SK Telecom (SKT) has launched a joint independent AI cybersecurity consortium with Upstage, major domestic information security companies, and universities. SKT formalized the partnership by signing a memorandum of understanding (MOU) on the 7th to cooperate on AI information protection technologies.

A total of 11 organizations are participating in the consortium. The participating companies are Upstage, SK Shieldus, Secui, AhnLab, Raonsecure, Genians, and Piolink, while the participating universities are Korea University, Soongsil University, and Pusan National University.

Many of the organizations in the consortium have previously formed a consortium for the government's call for projects to develop a cybersecurity-focused AI foundation model. An SKT official said the group was not selected for that project at the time.

The SKT official said the consortium was formed based on the collaborative ties established during the call for projects. As a result, the partnership built during the government project application process has now led to the launch of this consortium.

The agreement aims to expand the cybersecurity capabilities of SKT's A.X K series and Upstage's Solar, which are the models advancing to stage 3 of the government's independent AI foundation model project. The models targeted are SKT's A.X K series and Upstage's Solar.

The consortium plans to train the two models on field data from security companies, have universities verify their safety, and then apply them to participating companies' security products and services to confirm the results. The data used for training includes malware analysis data, software vulnerability analysis data, and security operations data held by the participating companies, all of which were generated in real security environments.

The goal of this effort is to improve AI's ability to understand and judge security situations. The training method is divided into pretraining and post-training.

Pretraining will be conducted to strengthen the model's basic knowledge using security data. Post-training aims to improve its ability to perform actual security work, including vulnerability analysis and patching, security operations center incident response, and the use of security tools.

The participating companies will collaborate by feeding the AI model with the security data and field experience they each hold. SKT plans to systematically train security-domain data into its next model, A.X K3, and also further strengthen the data needed for the safe operation of its AI service for everyone, 'Moeumui AI.' Upstage plans to intensively train security data for vulnerability detection and analysis into its next Solar model, which will be able to analyze large-scale code and long-term logs.

Security companies are supplying assets accumulated in monitoring and operations environments. SK Shieldus operates the integrated security operations platform 'Secudium,' which analyzes 17 billion threat events in real time every day. AhnLab holds more than 2.5 PB of security data.

Companies in security infrastructure and diagnostics are also contributing their technologies and data. Secui provides high-performance firewall solutions. Raonsecure provides penetration testing and security data.

Genians is providing security solution operations data and a post-training dataset. Piolink is providing attack validation and detection rule generation technology. These participating companies will bolster SKT and Upstage's next-model security performance by supplying field-based assets such as monitoring, firewall, penetration testing, operational data, and detection technologies.

SKT and Upstage plan to continuously accumulate the latest threat data and reflect the accumulated data in model training. Through this, they aim to strengthen their ability to respond to new types of attacks.

The AI models trained in this way will be applied to the participating companies' security products and services. They will then be evaluated in actual operating environments.

The main areas for proof of concept are zero-day vulnerability analysis and real-time security monitoring. The two companies plan to verify the field applicability and performance of the AI models in these areas.

As a way to verify the safety of the AI models, they will apply 'mutual red-teaming.' This method has A.X K and Solar take turns playing the role of attacker and probing vulnerabilities through mutual attacks.

Cases discovered in this process will be reused as training data. In other words, vulnerability cases identified during the safety verification process will be fed back into training.

During the development of A.X K2, SKT built its own red-teaming automation system, 'SERT(Self-Expanding Red-Teaming).' SKT used 'SERT(Self-Expanding Red-Teaming)' to generate and train on about 15,000 attack-response data points, and plans to apply mutual red-teaming to 'SERT(Self-Expanding Red-Teaming)' as well.

Upstage plans to use 210,000 pieces of its own high-difficulty and safety data, along with an AI alignment system for not responding to dangerous requests, to strengthen security functions.

The participating universities will be responsible for the design and evaluation of red-teaming. Korea University will handle the AI's executable-file analysis capabilities and attack defense capabilities, Soongsil University will handle AI security performance evaluation standards and defense against bypass attacks on guardrails, and Pusan National University will be in charge of verifying the performance and safety of next-generation and lightweight models.

The participating organizations plan to promote regular technical exchanges and identify joint AI information protection research projects. They also plan to review participation in related projects.

Yoo Kyung-sang, head of SKT AI CIC, presented the model's inference range and depth as the key standard for the level of security AI. He said the company aims to use models proven in the independent AI foundation model project to demonstrate real-world security effectiveness with domestic information security companies and universities, and to show the practical results of national AI models in cybersecurity as well.

Source: IT DAILY · Seong Won-young
Original: https://www.itdaily.kr/news/articleView.html?idxno=242078

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.