Summary
On May 1, 2026, Korea’s National Intelligence Service revised and promulgated the National Cybersecurity Basic Guidelines (국가 사이버보안 기본지침), removing the uniform network separation requirement and introducing tiered security controls based on information classification. In response to this environment, Quad Miners is advancing a technology and platform business transition toward context data-based AI security observability. Network Blackbox v5.0 analyzes original transaction data, behavioral baseline data, and detection explainability data together on a full packet capture foundation to provide the context required for threat determination.

Revised National Cybersecurity Guidelines and Network Visibility Requirements
On May 1, 2026, Korea’s National Intelligence Service revised and promulgated the National Cybersecurity Basic Guidelines (국가 사이버보안 기본지침). The document was previously titled the National Information Security Basic Guidelines (국가 정보보안 기본지침). Institutions subject to the guidelines include national agencies, local governments, offices of education and their affiliated organizations, public institutions, national and public schools, and military organizations.
The revision removed the internal network and internet network separation provision under the former Article 40. Under Article 39-2, information is classified into three grades — Confidential (C), Sensitive (S), and Open (O) — with security controls applied differentially by grade. Where security control guidelines are observed, information classified as Sensitive (S) may also be processed in external private cloud and generative AI environments. Article 131 specifies that EDR solutions adopted by each institution be integrated with security monitoring systems.
In a survey conducted by Boannews from July 16 to July 20, 2026, 54.2 percent of 1,072 respondents identified securing encrypted traffic visibility and continuous monitoring under N2SF adoption as the most difficult requirement to implement (multiple responses permitted). In the same survey, 35.5 percent responded that they had not yet established a specific approach to encrypted traffic visibility and continuous network monitoring, while 21.5 percent selected upgrading existing network security equipment and newly adopting a dedicated NDR solution.
Transition to Context Data-Centric AI-Based Security Observability
Quad Miners is advancing a technology and platform business transition toward context data-centric AI-based security observability. The direction addresses a limitation of analysis centered on state information such as detection events and system logs, where separate manual investigation is required before the full flow and actual impact of an attack can be confirmed.
In line with the progression of security operations technology across AI for SOC, Agentic SOC, and Autonomous SOC, the company is extending its existing full packet capture capabilities into the area of context data provision.
Three Types of Context Data in Network Blackbox v5.0
Network Blackbox v5.0 is an NDR solution that provides AI-based security observability centered on context data acquired through full packet capture. It analyzes the following three types of context data together.
- Original transaction data — actual content and session information within network packets
- Behavioral baseline data — learned normal behavior patterns for each asset
- Detection explainability (XAI) data — explanatory information on the reasons and grounds for detection
This provides threat context covering who, when, what, and how. By combining context data with state information, the solution reduces false positives and supports security personnel in responding on the basis of evidence.
Detection, Analysis, and Response in a Single Workflow
Network Blackbox provides the following capabilities within a single workflow.
- AI-based anomaly detection
- Threat hunting
- Original content analysis
- Threat intelligence integration
- Automated response
Technology Development for Context Data-Based Autonomous Security Operations
Quad Miners is developing integrated context analysis technology that connects Elastic Stack with LLMs. The company plans to verify the effectiveness of context data-based autonomous security operations through this work and is defining a new product roadmap that brings the verified technology in-house as proprietary technology.
This content was reconstructed from facts objectively verified in a feature article published by Boannews on August 3, 2026, under the byline of reporter Won Byung-chul