"AI hacking must be blocked with AI that understands security."
Seung-kyung Lee (이승경), head of AI development at AhnLab, said at a media briefing held by the company on Tuesday that AI is changing the speed of vulnerability attacks. He made clear that the solution is to use AI to block attacks that use AI.
But he drew a line, saying there is a prerequisite. He said a defense network must be built with AI specialized in security. Lee stressed that to create specialized AI, AI must first understand security, and that data is the key.
According to him, AhnLab structured scattered security knowledge such as threat intelligence, indicators of compromise (IOC), security monitoring information and technical support information into a form AI can analyze. Based on that, AI collects, screens and investigates many security signals to filter threats that need to be verified. It forms investigation hypotheses based on attack scenarios and finds needed data on its own. It decides the next investigation target based on findings and repeats analysis. Through this process, scattered security signals are connected into a single attack flow.
AhnLab said it analyzes about 190 million security objects a month and processes 50 billion tokens based on 2.5 petabytes of security data, 13 security-specialized models and about 60 AI agent tools. It defined security objects as units of data analyzed by AI, such as logs, events, alerts, files, IPs and sessions.
AhnLab is also developing various tools to respond to offensive AI, and AI pentesting is one of them.
Lee said, "AI pentesting verifies the possibility of intrusion and assesses risk without carrying out an actual attack. It analyzes the target environment, establishes an intrusion plan, selects the tools needed and carries out the attack, and if it fails it tries again. If an attack AI decides its next action on its own and searches for attack points, a defense AI decides its next investigation target on its own and tracks traces of attacks."
Lee also stressed that cyber security in the AI era will become a reasoning-centered competition. "Cyber security competition in the AI era will be decided by AI reasoning ability, not by security analysts' capabilities or simple automation of tasks," he said. "Reasoning here does not mean only large language model reasoning. The key is specialized reasoning that combines security knowledge and situational judgment intelligence."
He added, "As AI autonomously performs security, control should also be designed together. AhnLab implemented a controlled autonomy system with four devices: auditing, access control, policy protection and approval."
AhnLab also stressed at the briefing that it will push forward its security platform 'AhnLab AI Plus' focused on software as a service (SaaS).
It is also moving in earnest to expand 'AhnLab AI PLUS Endpoint' and 'AhnLab AI PLUS SecOps.'
AhnLab AI PLUS Endpoint is a protection platform that integrates and provides EPP and EDR on a SaaS basis. It supports existing customers in making a stable transition to a SaaS environment while maintaining protection continuity, and expands protected targets from PCs to servers, virtual environments, containers and mobile.
AhnLab AI PLUS SecOps is an AI-based security operations platform that connects various security data and operational functions centered on XDR, MDR and AI SOC. It links security signals generated from AhnLab products and third-party solutions, including endpoints, networks and cloud, to analyze attack context and priorities. It supports prevention, detection, investigation and response to 이어지도록 support a single operational flow.
Lee said, "AI-native security is already applied to products. It is not a future vision," adding, "Through the AhnLab AI Plus SecOps platform, it is being applied in actual customer security operations."