Lee Jin-won (이지원), an executive director at F5 Korea

[DigitalToday reporter Chi-gyu Hwang] "Many companies are running AI proof-of-concept projects, but the share moving into real-world use is still not large. That is because they are not prepared for how to strengthen and maintain security. If there are problems with governance or protecting important corporate data, it could become a risk."

Lee Jin-won (이지원), an executive director at F5 Korea, made clear in a recent interview with a reporter that it is difficult for enterprise AX to move beyond testing into a settling-in stage without resolving security risks. Many still have not found clear answers, he said.

He said it is not unrelated to the fact that AI security differs from existing security in its approach.

Lee said, "With existing security, you can deploy a web application firewall and respond to vulnerabilities, but with AI security, not only vulnerabilities but also prompts entered into AI services can be a problem. Inappropriate prompts are not vulnerabilities from a traditional perspective, but they are not something you can simply overlook in terms of risk. Sensitive information can leak even when there are no vulnerabilities." He added, "You cannot block these issues simply by controlling layer 7 security that handles applications. It is an area where development teams also need to pay attention, beyond security."

Even though AI is fundamentally different from existing IT systems, he said corporate security managers often still approach AI security as if they can solve it by deploying solutions as they used to.

Lee said, "You need to understand the entire AI architecture and, based on that, set priorities for security threats. What F5 considers important is workshops that help customers learn more about AI. At headquarters level, we have also started an AI academy program." He repeatedly stressed that AI must be understood in depth to secure AI.

He also said, "To properly block prompt injection attacks that manipulate generative AI systems based on large language models through natural-language commands, you need technical depth. You need to respond in a tailored way by segment and by point." He added, "F5 is developing solutions separately depending on where it sits."

An approach of building systems first and treating security as an afterthought is also hard to apply to AI. Lee said, "AI security must go together with AI from the beginning. Without security, you cannot move to the production stage. In the field, awareness is spreading that AI security needs to be prepared in advance."

F5, which has grown with application delivery and application security as its main strengths, has recently been making AI security a new growth engine and stepping up an aggressive push. It is rolling out new AI security solutions one after another through in-house development as well as mergers and acquisitions. It recently introduced a patch management solution, F5 Insight.

Lee said, "Anthropic Mythos can automate access to important information in addition to penetration. From a corporate perspective, patches need to be applied quickly. F5 also changed its patch disclosures from quarterly to monthly." He added, "F5 Insight links with LLMs to support AI-based operations and analysis."

F5 says effective AI security requires covering 3 control points: the front door, orchestration and inference.

The front door refers to the chatbot interface environment used by users. To secure this area, F5 redesigned its existing WAF architecture and built a new neural-network layer trained on its own data while maintaining a foundation based on signatures, indicators of attack and risk intelligence.

Orchestration is the area where AI is linked with internal systems to add context to prompts. API security is key.

To strengthen security in this area, F5 acquired Calypso AI last year and introduced "F5 AI Red Team" and "F5 AI Guardrails."

Inference focuses on preventing wrong decisions at the front end of inference. Lee said, "If you solve problems at the front end of inference, you can increase efficiency." He added, "F5 is investing in networking, security and load balancing capabilities that support enterprise AI to scale efficiently across the latest AI factory architecture."

Lee also highlighted an integrated platform strategy.

He said, "F5 ADSP (Application Delivery and Security Platform) provides F5 solutions on a single platform and supports enterprises to deploy security policies consistently from a single console and carry out updates in one go. Considering the rapid surge in AI-driven traffic, it also provides AI traffic visibility. Beyond distinguishing between human and AI traffic, it can also identify whether AI traffic is ChatGPT or Claude," he explained.

F5 also sees significant potential in detecting AI outside corporate control, known as Shadow AI. For this, F5 recently acquired Sure Path AI, which detects Shadow AI. With the acquisition, F5 now has an integrated AI security platform spanning guardrails, red team, AI remediate and Sure Path AI, the company said.

As part of expanding in the South Korean market, F5 will also build a POP (Point of Presence) directly in South Korea. A POP is global network infrastructure that F5 has built at major hubs worldwide to provide its F5 Distributed Cloud Services. Lee said, "If a POP is introduced in South Korea, we will be able to provide customers with more competitive services in terms of software-as-a-service platform cost and quality."

F5's moves toward AI are expanding beyond security into governance and cost management. F5 strengthened the capabilities of "F5 AI Gateway" and integrated them into "F5 AI Security Platform."

F5 AI Gateway provides an integrated control plane that applies consistent policies to all AI requests and manages how AI models, agents and tools are accessed and used. The company said this can also improve cost efficiency in large-scale AI operating environments.

Lee said, "Organizations that cannot track token usage by team, model and provider find it difficult to properly assess the value and costs of using AI. F5 AI Gateway supports effective control of tokenomics."

Keyword

#F5 #F5 Korea #LLM #F5 AI Gateway #Calypso AI
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.