주메뉴바로가기본문바로가기
비즈한국 비즈한국

Mythos Shock
③ The Era of AI-driven Hacking: How Are We Responding?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →
Editor's Note
For the past few decades, humans have been the primary agents discovering and defending against security vulnerabilities. If AI can now take over that role, whose hands will the attack and defense of cyberspace lie in moving forward? The 'Mythos Shock' is an incident that has posed this question to both industry and government. We examine the industry turmoil and responses triggered by the Mythos Shock and look at the challenges facing South Korea.

[비즈한국] Following the Mythos Shock, both the public and private sectors are accelerating the reorganization of their response systems under the principle that "AI attacks must be blocked by AI." The financial sector is introducing autonomous AI penetration testing and AI-based security monitoring, while the public sector is also accelerating the transition of its network security architecture under the premise of the AI era.

As an era begins where AI discovers vulnerabilities and designs attack paths, the methods for cybersecurity response are also changing. A view of a data center. Photo=Microsoft

The financial sector is the fastest to act. As a core national infrastructure where customer information and capital flow are connected in real-time, finance is considered the field where damages could manifest most quickly as AI increases the speed of attacks.

Woori Financial Group recently adopted 'Xint Web,' an AI-based autonomous black-box penetration testing solution from Offensive security firm Theori. This method finds weaknesses by probing the outside of a service like a real hacker, without any internal system information. KB Financial Group is also strengthening its AI-based response by expanding its self-developed AI penetration testing agents and Zero Trust-based security systems.

The Bank of Korea has also begun transitioning to an AI-based security system by introducing equipment from U.S.-based Palo Alto Networks, an initial participating company in 'Project Glasswing,' an international cooperation group for responding to Mythos.

“AI Attacks Must Be Blocked by AI”… Domestic Response in Full Swing

While companies are taking technical measures, the government has also begun establishing institutional foundations. Following the emergence of Mythos, the Financial Services Commission decided to temporarily relax network separation regulations for the use of AI for security purposes. The policy targets 49 financial companies with total assets of over 10 trillion won and 1,000 or more permanent employees, offering a one-year regulatory easing following an evaluation of their security management capabilities. The Ministry of Science and ICT is also focusing on securing AI-based security capabilities, such as discussing cooperation plans with Anthropic, including securing access rights to Mythos.

Experts find the essence of the Mythos Shock not in the "emergence of fully automated AI hackers" itself, but in the fact that the way security tasks are performed is fundamentally changing. Yang Jong-heon, Division Head at big data analysis AI firm S2W, pointed out, "The core is not that full automation is complete right now, but that the unit cost, speed, and repeatability of security tasks have started to change." He added, "This change could shake not only the way vulnerability researchers work but also the entire software supply chain and patch management system."

The explanation is that while human competitiveness in the security sector previously stemmed from the ability to discover vulnerabilities, it will become increasingly important in the future to verify the results found by AI, judge the actual risk, and determine the priority of response.

The Mythos Shock showed that AI can elevate the speed and scale of exploring and analyzing security vulnerabilities to a level incomparable to what existed before. Photo=Pixabay

Even if AI performs a significant portion of attacks and defenses, the final responsibility ultimately returns to humans. This is why a governance system for managing AI is emphasized as much as technological development. Choi Byung-ho, a professor at the Korea University AI Research Institute, said, "In a realistic system, humans and AI must cooperate, and it is inevitable that the structure will hold the cooperating human responsible." However, he added, "Because that governance system is not yet complete, we are helpless when such incidents occur," and warned, "The global community is in a state where the Tier-1 security market is highly likely to be incapacitated."

Division Head Yang noted, "For companies, what is needed first is the visibility of assets and code," adding, "If you don't know what systems you are operating or what open-source libraries you are relying on, it is difficult to connect vulnerabilities found by AI to actual risks." He meant that even if AI finds a large number of vulnerabilities, it is useless if there is no foundational strength to translate and interpret them as actual risks to the company's systems.

Yoo Jun-gu, a senior research fellow at the Sejong Institute, also diagnosed in a related report that "the core of security for major data-based infrastructure does not lie in raising external firewalls, but in how to control permissions when internal accounts are compromised." He argued that instead of assuming perfect security, the direction should be to design rigorous verification steps that attackers must pass through to achieve their goals.

Prioritizing ‘Access and Control’ over Performance… Government Also Weighs Security-Specialized AI

So, how close can South Korea get to Mythos-class top-tier models? Experts suggest that even if access rights are secured, it will not be easy to directly utilize Mythos-class frontier models domestically. This is because as overseas frontier AI is increasingly managed as a national strategic asset, the possibility of restricted access is growing.

Although the Korea Internet & Security Agency (KISA), Samsung Electronics, and SK Telecom have secured access rights to Mythos from Anthropic, the prevailing view is that room for long-term utilization could gradually decrease as the U.S. shifts its policy toward managing frontier AI as a strategic asset. Although the U.S. Department of Commerce lifted export controls on Mythos5 and Fable5 general models after 18 days in June, the application of strengthened safeguards means the scope for utilizing them in security research has actually narrowed.

Directly developing or stably utilizing Mythos-class frontier models comes with constraints in computational resources, costs, and overseas export controls. Major participants in Anthropic's security enhancement initiative, 'Project Glasswing.' Photo=Anthropic Blog

However, it is pointed out that jumping into a competition to develop super-large models at the same level as Mythos is not a realistic solution. Kim Ho-won, president of the Korea Institute of Information Security & Cryptology and a professor at Pusan National University, said at a seminar on seeking directions for cybersecurity development on the 9th of last month, "If we blindly start developing our own Mythos, we could get caught in a chicken game, and if we use foreign models, we fall into a data sovereignty dilemma." He suggested, "An agent orchestration-based small specialized model (sLLM) strategy that organically controls multiple AIs could be a realistic alternative."

Development capacity is also limited. This is due to the massive computational resources and investment costs involved. Deputy Prime Minister and Minister of Science and ICT Bae Kyeong-hoon mentioned at a press conference marking his first anniversary in office last month, "It is difficult to develop a Mythos-class frontier model with the level of support currently provided for independent AI foundation model projects," adding, "It is estimated that about 10,000 Vera Rubin-class GPUs are needed, and the current price alone is around 3.5 trillion won."

The problem is not just cost and technology. The fact that access itself can be swayed by political decisions has also emerged as a new risk. Wang Yun-jong, a professor of international business at Dongduk Women's University, evaluated the U.S. blocking of access to Anthropic by saying, "The 'switch-off risk,' where another country's generative AI service can be discontinued overnight, has become a reality." He continued, "Sovereign AI needs to be approached from the perspective of being a national-level backup system in case overseas AI access is restricted, rather than a means for market competition."

Additionally, as the predictability of regulations has significantly decreased, he advised that domestic companies should include the U.S. administration's export control measures as an explicit 'force majeure' clause in contracts with global clients.

Overseas, national and corporate-level response systems are already taking shape. On the 27th of last month, Microsoft (MS) unveiled its autonomous AI attack response project 'Perception' and security-specialized AI models, and launched the External Red Teaming Alliance (EXTRA), in which institutions like the Korea Advanced Institute of Science and Technology (KAIST) participate, signaling the start of full-scale AI security competition.

The Mythos Shock foretells an era of competition not just in AI performance, but in utilization and control. For South Korea, the remaining tasks are how to build security systems and institutional responses alongside securing technology.

Accordingly, the government plans to pursue a 'two-track strategy' that examines the possibility of frontier AI development separately from the independent AI foundation model project, while prioritizing the development of 'security-specialized AI' using existing models. Deputy Prime Minister Bae stated, "Even if we cannot build a frontier model right away, we can create a security-specialized AI model that checks for various vulnerabilities by fine-tuning currently held models with security data," adding, "We plan to develop it within this year and start applying it in the public sector."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
강은경 기자

기술과 산업을 취재하고 씁니다.

gong@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지