Naru Security, a cyber threat management company, said on Tuesday it will carry out the Korea Internet & Security Agency's project to detect companies in regions hit by intrusion incidents and diagnose vulnerabilities.
The project focuses on constantly monitoring cyber threats facing small and micro businesses across the country, and on identifying early signs of intrusion and vulnerabilities to prevent damage.
Through the project, Naru Security plans to use network data to identify security blind spots that have not been revealed and find companies suspected of intrusions, providing tailored threat response measures suited to each company's environment. It will promote constant monitoring and detection of network threats by region and area, collect network communication information to identify attack groups, attack bases, points of origin, affected companies and the scope of damage, and detect and analyse hacking infrastructure and suspicious IP addresses. It also plans correlation analysis of threat intelligence based on detected data, and provision of analysis results and response reports for companies suspected of being affected.
Detected data will be further analysed by linking it to threat intelligence held by Naru Security. Naru Security will combine its proprietary network flow analysis technology accumulated over a long period, operational know-how for its breach assessment service ZeroTiCA, and hands-on experience investigating and responding to real intrusion incidents. It will add the know-how of experts who have built experience at KISA's intrusion incident investigation and response sites to provide measures suited to small businesses.
Naru Security plans to use the project as an opportunity to expand its breach assessment and verification capabilities, which it has provided mainly to large companies, to regional small businesses. It also plans to advance a tailored cyber threat response model for companies that lack security personnel and budgets.
Jae-kwang Lee (이재광), head of Naru Security's threat response centre, said small businesses need a system that confirms through data what threats they are currently exposed to and supports continuous checks and management, rather than being presented with complex security technology. He said the company will work with KISA to build a highly effective threat response model that can eliminate security blind spots for regional small businesses.