Press Release DailySecu

Quad Miners CTO Kim Yong-ho Presents Context-Based Security Operations Strategy at Financial Sector CISO Seminar

2026. 04. 12. Strategic Planning Division

Summary

Quad Miners CTO Kim Yong-ho presented a context data-driven security operations strategy at a seminar for financial sector CISOs held in Seoul on April 9. The seminar, jointly hosted by DailySecu, Quad Miners, and AI Spera, addressed Living off the Land (LoL) attacks that exploit legitimate tools and the limitations of fragmented security systems. The presentation also covered Quad Miners' context data-based AI detection technology, the architecture of Network Blackbox 5.0, and a case study of integration with AI Spera's Criminal IP.      

CISO Seminar Held for Financial Sector

Quad Miners, together with DailySecu and AI Spera, held a CISO breakfast seminar at the Conrad Seoul Hotel in Yeouido, Seoul, on April 9, 2026. The seminar, themed "Visualizing and Responding to Internal and External Security Threats in the Financial Sector," was attended by approximately 40 CISOs from financial institutions. Quad Miners CTO Kim Yong-ho delivered a presentation titled "Beyond Visibility: Case Studies in Building Actionable Security Response Systems."

Living off the Land (LoL) Attacks and the Limits of Fragmented Security Systems

The presentation identified Living off the Land (LoL) attacks — which exploit legitimate management tools such as VPN, RDP, and PowerShell — as a key threat. These attacks progress through initial intrusion, privilege escalation, lateral movement, persistence, and data exfiltration. Because they rely on legitimate tools, signature-based security equipment alone struggles to identify them. It was also noted that when multiple security solutions generate alerts independently, integrated data analysis and prioritization become more difficult.

Context Data-Based AI Detection Technology

The presentation explained that conventional detection methods rely primarily on five-tuple information — source/destination IP, port, and protocol. As an alternative, Quad Miners introduced its context data-based AI detection technology, which analyzes the actual content and meaning of behavior within transactions. This technology is being developed based on a memorandum of understanding (MOU) and joint research projects with KAIST, the Korea Institute of Science and Technology Information (KISTI), and Gachon University, and is planned for future application as a commercial product feature.

Architecture and Capabilities of Network Blackbox 5.0

Network Blackbox 5.0 was introduced as a platform that reconstructs transaction-level information — including sessions, content, files, emails, and web access traces — based on full packet capture, and connects this information to threat behavior. The product architecture consists of three layers:

  1. Bottom layer: Full packet capture
  2. Middle layer: Threat indicator identification
  3. Top layer: Context-based intelligence

The operational workflow was described as connecting full packet capture and collection, detection, hunting, forensics, and response within a single data framework. Network Blackbox has also obtained a security functionality verification certification from South Korea's National Intelligence Service. [Fact to be confirmed: exact certification date]

Zero Trust Integration and Case Study with AI Spera's Criminal IP

The presentation referenced the Korea Internet & Security Agency's (KISA) Zero Trust Guideline 2.0, which presents six core elements alongside "visibility and analytics" and "automation and integration" as cross-cutting functions. It was noted that Network Blackbox can serve as a Policy Information Point (PIP) within the Zero Trust logical architecture.

A case study on the integration between AI Spera's threat intelligence service, Criminal IP, and Network Blackbox was also introduced. When an event detected by Network Blackbox is selected, the corresponding IP's risk score and summary information from Criminal IP can be viewed immediately, and detailed parameter-level data can also be reviewed on the same screen.

   
This content was compiled based on facts objectively verified from a news article by DailySecu, bylined by reporter Kil Min-kwon.
#NDR #Network Blackbox #Cybersecurity
Source · DailySecu
View Original Article
← Back to News