AhnLab ISF 2024: Innovation Achieved Through AI and Unified Security
As autumn reached its peak, AhnLab prepared tailored security strategies aligned with the latest security trends and met with security personnel from client companies. On September 26th, AhnLab's Unified Security Conference 2024 (AhnLab ISF 2024) was held at the Grand InterContinental Hotel in Seoul. Throughout this year, AhnLab has focused on advancing security solutions and AI technologies, as well as strengthening platform-based integration in line with global trends. This event also served as an opportunity to introduce more specific and essential security strategies related to AI and unified security. Let us take a closer look at the event.

At AhnLab ISF 2024, methods to implement stronger and simpler security using AI were introduced under the slogan "AI-Augmented Security. Simplified." Starting with a welcome speech by AhnLab CEO Suk-Kyoon Kang, the event featured keynote speeches by CTO Sung-Hak Jeon and Director of Product Service Planning Chang-Hee Kim, followed by track presentation sessions on the themes of ▲Proactive, ▲Low-Friction, and ▲Unified.

Photo 1. Participants waiting to enter AhnLab ISF 2024
In his welcome speech, CEO Suk-Kyoon Kang stated that AhnLab has been enhancing its detection and response capabilities by applying AI technologies to its products and platforms in various ways over the past few years. He emphasized, "In response to the increasing sophistication of cyber threats and the complexity of security, ‘artificial intelligence (AI)’ and ‘security operational efficiency’ are being highlighted as key trends. AhnLab also aims to enhance security efficiency through unified security to increase clients' business productivity and advance our AI technology in that context."
He continued, "Today, we are officially introducing AhnLab PLUS for the first time, a unified security platform that combines six platforms: endpoint, network, cloud, services, security operations, and cyber-physical system (CPS). It will continuously develop integration between products and platforms following four guiding principles of ▲Proactive, ▲Low-Friction, ▲Unified, and ▲Security, contributing to enhance our clients' business productivity."
Additionally, CEO Kang emphasized the importance of collaboration among people and organizations beyond just product and technology integration. He added, " One organization alone cannot solve all security challenges, so multiple organizations must join forces to counter evolving threats. I hope that AhnLab ISF 2024 will play a key role in leading this collaboration."

Photo 2. AhnLab CEO Suk-Kyoon Kang emphasized the need for a unified security platform and the importance of collaboration between organizations.
After CEO Kang's welcome speech, AhnLab's Head of Research Center, Eric Jun, delivered a keynote speech on the topic of "The Threats of Generative AI and Future of AI-Powered Security." Mr. Jun shared strategies for safely guiding future security using AI, as AI technology and AI-based attacks continue to evolve.
Mr. Jun advised that attackers are increasingly utilizing AI technologies in their attacks, such as distributing phishing emails, developing malware, and creating deepfake videos. To defend against these threats, defenders must continuously consider how to detect such attacks using AI-powered security solutions from a defensive perspective.
He also added, "AhnLab applies AI technologies to AhnLab EDR, MDS, V3 Mobile Security, and XDR to learn from URL information and event logs. This enables the detection of malicious activities, phishing emails, and behavior-based anomalies, providing threat intelligence and proactive responses. In the case of AhnLab XDR, users can leverage the generative AI, ‘AhnLab Annie AI,’ which serves as an AI security assistant. Upon entering user-input prompts, AhnLab Annie AI supports users' security operations by providing information on security events and actions taken during off-hours, whether reports were generated, etc."

Photo 3. Eric Jun, Head of Research Center, shared specific strategies for countering threats abusing generative AI.
The second keynote speaker, Head of Product & Service Planning Division, Changhee Kim, presented on the topic of "Empowering the Future of Cybersecurity: Everything Everywhere All at Once." This session focused on the challenges organizations face in a rapidly changing business environment and the solutions proposed by AhnLab.
Mr. Kim stated, "As cyber threats evolve, the simultaneous increase in cloud usage, the rise of remote work, and the expansion of attack surfaces are causing most organizations to struggle with efficient security operations and improving productivity. To overcome these challenges, unification is key. AhnLab PLUS operates by integrating various security platforms, such as endpoints, networks, and clouds with centralized management capabilities. AhnLab XDR is positioned at the top, collecting and analyzing data from multiple security domains to provide optimal risk management solutions."
He further explained, “AhnLab is enhancing the AhnLab PLUS platform by adding new products and services, such as device control, container security, and managed detection and response (MDR) in the endpoint, cloud, and service domains. With future-oriented offerings like Zero Trust Network Access (ZTNA) and Attack Surface Management (ASM, AhnLab aims to reduce security complexities and safely protect clients' work environments.

Photo 4. Changhee Kim, Head of Product & Service Planning Division, presented solutions to address security threats in the business environment.
Protect Today for Resilient Tomorrow
Myeong Su Lee, Team Leader of A-FIRST (AhnLab Forensic Intelligence ReSearch Team) at AhnLab, gave a presentation on the topic "Ransomware ran somewhere," discussing ransomware trends, incident cases, and response strategies up to the third quarter of 2024.
Mr. Lee stated, "Recently, there has been a surge in ransomware attacks exploiting vulnerabilities, with notable examples including attacks on software vulnerabilities in ESXi, ScreenConnect, Qlik Sense, Windows, and PHP. As ESXi is a virtual machine created by VMware, the entire system becomes inoperative if it is infected with ransomware, leaving the victim with no choice but to negotiate. For this reason, many attackers are targeting ESXi as a primary target."
To respond to ransomware, Mr. Lee advised that it is essential to have processes in place, such as preparation, real-time defense, intrusion detection, and incident response. He also recommended referring to ransomware response guides provided by the Korea Internet & Security Agency (KISA) and AhnLab, and continuously keeping up with the latest trends and response methods.
Mr. Lee concluded, "Just as Mark Twain famously said, 'Stock investment requires caution every month,' ransomware security also requires constant vigilance."

Photo 5. Myeong Su Lee, Team Leader of A-FIRST at AhnLab, introduced ransomware trends and response strategies up to the third quarter of this year.
Seung Kyung Lee, Team Leader of AhnLab's Artificial Intelligence Team, presented on the topic of "AI in Security: AI-Augmented Security," outlining the future direction of security technologies incorporating AI including large language models (LLM). He particularly emphasized the intersection between security and AI, focusing on how AI can be applied to security and its role in alleviating challenges in security operations.
Mr. Lee stated, "In security, the scale and complexity of data pose significant challenges, and similar to the big data era, AI can be an alternative solution to these problems. Various problems arising in security operations can be solved through AI-augmented security, and AhnLab provides this solution in the form of a service platform based on a common model."
Lee identified two major issues faced in security operations: "threat overload" and "security tool complexity." Regarding how AI can solve these issues, he explained, “AI addresses the problem of threat overload by moving away from passive and reactive detection methods to proactively identifying potential threats early. By analyzing data to detect abnormal behaviors, security analysts can respond more effectively to potential threats. In the case of security tool complexity, AI can simplify the process for users. While traditional security tools require users to analyze information with complex menus, AI assistants can automatically analyze the necessary data and suggest appropriate countermeasures, reducing the burden on security experts and allowing them to focus on their core tasks."

Photo 6. Seung Kyung Lee, Team Leader of AhnLab's AI team, explained the future direction of security technologies incorporating AI.
Geon Yong Lee, Team Leader of AhnLab's Convergence Product & Service Planning Team, introduced ways for security personnel to build a more efficient security operation environment through AhnLab XDR in the presentation session titled "f(X)D+R=0perational Efficiency, AhnLab XDR."
Mr. Lee explained that AhnLab XDR supports efficiency in three main aspects: ▲unified log analysis, ▲risk detection and notification, and ▲response. He stated, "AhnLab XDR collects and integrates data from various sources to help security personnel detect potential threats early. It also reduces unnecessary alerts and uses machine learning (ML)-based behavior detection technology to identify more dangerous alerts. In addition, AhnLab XDR supports recommendations and automated responses based on AI models, focusing on improving the work efficiency of security personnel through the upcoming Managed XDR (MXDR) service."
Mr. Lee added, “AhnLab XDR aims to bring risks to a zero state by analyzing and responding to all risks. There are plans to expand support to private cloud services in the second half of this year in addition to the currently serviced public cloud."

Photo 7. Geon Yong Lee, Team Leader of Convergence Product & Service Planning Team at AhnLab, introduced ways to enhance business competitiveness through AhnLab XDR.
There was also a presentation by a security manager from Golfzon, a client of AhnLab that has adopted AhnLab XDR. Jeong Hoon Kim, Team Leader of Golfzon's Information Security Team, shared the background and operational expertise of adopting AhnLab XDR at Golfzon.
Mr. Kim stated, “AhnLab XDR can easily integrate with EDR and allows for rapid deployment in a SaaS model. Golfzon integrates EDR into XDR for centralized management across various networks including the Internet network, IDC, AWS, and electronic financial network, significantly reducing security risks. This was made possible through threat event correlation analysis utilizing XDR and addressing root causes."
According to Mr. Kim, since adopting AhnLab XDR, Golfzon has experienced the benefits of blocking suspicious malicious IPs, abnormal VPN login attempts, and brute force attacks, as well as enhancing firewall policies and deriving intuitive and meaningful results through security solution log correlation analysis.
Mr. Kim noted, "Using XDR does not mean that all risks are automatically resolved; there’s still the burden of prioritizing risks and responding directly. To address this issue, Golfzon has also adopted AhnLab MDR to manage endpoint threats and reduce the security team's workload with real-time monitoring and response support from external experts."

Photo 8. Jeong Hoon Kim, Team Leader of Golfzon's Information Security Team, introduced the benefits gained from adopting AhnLab XDR in Golfzon's system.
Ha Young Yang, Head of ASEC (AhnLab SEcurity intelligence Center), presented on the topic of "Inside Out: The Anxiety in Cyber Threat Intelligence." Mr. Yang explained that the reason we feel anxious in security is because we know threats are lurking, but we don’t know when, where, or how breaches will occur. This means that if threats can be anticipated and prevented, the anxiety felt by security personnel would decrease.
From this perspective, Mr. Yang introduced the latest threat trends in three categories: ▲vulnerability attacks, ▲phishing attacks, and ▲InfoStealers. He shared real cases and analyses conducted by ASEC for each attack type. Additionally, he covered how AhnLab TIP (Threat Intelligence Platform) provides intelligence on the latest threats.
He emphasized, "Unlike other security solutions that respond after a threat occurs, AhnLab TIP approaches from a proactive perspective by identifying and preventing threats in advance. It not only provides content such as analysis reports but also offers various features llike ▲IoC feeds, ▲threat group analysis, ▲sandbox analysis, and ▲dark web monitoring, helping companies and organizations proactively understand and prevent cyber threats."

Photo 9. Ha Young Yang, Head of ASEC shared strategies for preparing against anxiety-causing cyber threats using AhnLab's cyber threat intelligence (CTI).
Simplify and Secure: Seamless Security Solutions
Sang Eon Oh, Head of Solution Consulting Division at AhnLab, emphasized in the presentation session "Why and How to Adopt CTEM (Continuous Threat Exposure Management)" that CTEM is a key strategy for controlling threat environments and strengthening organizational security.
According to Mr. Oh, as security management areas have expanded due to the increase in remote work and the adoption of cloud environments, security must move beyond the traditional focus on data centers and office networks to cover a broader range of areas. CTEM is a new approach to address these environments by identifying attack surfaces in advance, prioritizing them, and continuously managing them.
Mr. Oh stated, "The core of CTEM is proactive security management. This means not only adopting security solutions but also continuously monitoring and managing the exposed risks to an organization's assets. Of course, basic measures, such as vulnerability management and patch management, should not be neglected."
He added, "AhnLab has applied the CTEM concept to AhnLab XDR. Through this, AhnLab XDR integrates security solutions across various areas such as endpoints, networks, and clouds, and connects them with vulnerability information and threat intelligence to enable comprehensive risk management. Additionally, automated response and risk prioritization can enhance the efficiency of security teams, and Managed Extended Detection and Response (MXDR) service can be offered to further strengthen an organization’s security capabilities."

Photo 10. Sang Eon Oh, Head of the Solution Consulting Division at AhnLab, emphasized that CTEM is crucial for controlling threat environments and strengthening organizational security.
Nam Ho Won, Head of the Technical Support Division at AhnLab, delivered a session titled "Things Working Hard or Things Hardly Working? (feat. Work Diet)." The session covered ways to respond to security threats and enhance work efficiency using AhnLab's endpoint protection platform, AhnLab EPP.
AhnLab EPP is a platform that integrates and manages various security functions, such as anti-malware, patch management, privacy protection, device control, and EDR, through a single agent. By doing so, it can reduce the burden on users’ PCs and improve management efficiency. In particular, advanced rule settings allow for automated responses to security events, minimizing manual intervention by security managers and enabling rapid response.
Mr. Won explained, "AhnLab EPP significantly contributes to improving a company's overall security posture by automatically detecting, removing, or updating vulnerable software. Also, automated response rules can be set for various scenarios, such as checking the real-time scan status of anti-malware, automatically quarantine of detected malware, and detection of suspicious activities related to personal information leakage."
He added, "AhnLab EPP also provides a gradual deployment feature for the safe distribution of security patches and engine updates. By applying patches or updates in stages, potential issues can be identified and addressed in advance, enhancing stability in a company’s endpoint security management.

Photo 11. Nam Ho Won, Head of the Technical Support Division at AhnLab, gave a presentation on responding to security threats and enhancing work efficiency using AhnLab EPP.
Tae Hwan Park, Head of ACSC (AhnLab Cyber Security Center), shared insights on the topic "Together with MDR," highlighting common cyber threat scenarios organizations face and the specific benefits that can be gained from adopting MDR.
Mr. Park explained, "Representative cyber threats identified in organizations include ransomware distribution incidents caused by brute force attacks, phishing attempts using tracking pixels hidden in emails, and damages caused by malware embedded in KMSAuto, a software used to bypass genuine product activation. Although companies are exposed to various cyber threats, they can receive assistance from AhnLab's expert analysis team through MDR services. The MDR team stays by the client's side, analyzing threats and suggesting response strategies. Additionally, the MDR premium service provides in-depth threat analysis and proactive threat hunting."
He emphasized that MDR services are applicable in various environments, including those with no network connectivity and cloud-based infrastructures. According to Mr. Park, companies can consult with AhnLab's sales team to explore service options that best fit their specific environment when considering the introduction of MDR services.
He suggested, "By adopting AhnLab MDR services, organizations can proactively respond to diverse cyber threats targeting the rapidly changing IT environment and enhance their overall security posture."

Photo 12. Tae Hwan Park, Head of ACSC at AhnLab, explained the benefits organizations can gain from implementing AhnLab MDR services.
Manage Less, Defend More
Kwang Woo Jung, General Manager of Strategic Product & Service Planning Team at AhnLab, delivered a presentation titled "Endpoint? And Point Security!," where he introduced a workspace security strategy optimized for hybrid work environments and the unification, linkage, and integration of endpoint security.
Mr. Jung pointed out, "As work environments expand, the requirements for endpoint security have also changed. Comprehensive security control across the entire infrastructure connected to endpoints is now necessary."
He outlined three essential requirements for endpoint security to ensure workspace security: ▲Platform-based, ▲User-centric, and ▲Integration. He explained, "AhnLab provides optimal endpoint security by implementing extended visibility, enhanced response capabilities, and reduced management and operational complexity through AhnLab EPP. Additionally, AhnLab EPP uses a flexible approach that integrates with servers and databases containing user information to identify devices based on user data. Furthermore, it offers syslog and APIs that allow for linkage and integration with various heterogeneous security products."
Jung emphasized that the most critical considerations in terms of endpoint security are "Consolidation" and "Integration." He noted the importance of thinking carefully about how to utilize and provide these two aspects from the user's perspective.

Photo 13. Kwang Woo Jung, General Manager of Strategic Product & Service Planning Team at AhnLab, explained a workspace security strategy optimized for hybrid work environments with a focus on endpoint security.
Byung Sung Yoon, Deputy General Manager of Convergence Product & Service Planning Team at AhnLab, led a session titled "Network PLUS: A to Z AhnLab ZTNA," focusing on the basic concepts necessary for adopting Zero Trust and the present and future of AhnLab ZTNA.
Mr. Yoon stated, "The key elements for adopting Zero Trust are ▲identifiers and identities, ▲devices and endpoints, ▲networks, ▲systems, ▲applications and workload, and ▲data. The cross-functional aspects that encompass these elements are ▲visibility and analysis and ▲automation and unification. The stages of Zero Trust are categorized as previous, enhanced, and optimized, and it is not possible to achieve the optimized stage in a short period. Therefore, the advancement of Zero Trust is only possible by repeatedly going through the stages of preparation, planning, implementation, and operation."
Additionally, Mr. Yoon added that AhnLab ZTNA includes the ‘ZTNA Manager,’ responsible for ZTNA policy and rule setting, authentication, and device verification, as well as ZTNA Gateway which handles connection, access control, and monitoring physically separated from each other. In other words, the control area and data area are completely divided, providing stronger security.
Mr. Yoon added, "By integrating AhnLab's firewall appliance XTG, EPP Agent, ESA (EPP Security Assessment), and V3 with these 2 areas, a much wider range of device information can be collected.” AhnLab ZTNA can be widely implemented in hybrid cloud and network separation environments, as well as in both on-premises and remote access settings in the future."

Photo 14. Byung Sung Yoon, Deputy General Manager of Convergence Product & Service Planning Team at AhnLab, introduced the concepts and implementation strategies of Zero Trust and ZTNA.
Young Jin Roh, Head of Cloud R&D Division at AhnLab, gave a presentation titled "Container-Centric Cloud Security: Latest Security Strategies Using SBOM and eBPF," proposing secure container operation methods based on SBOM and runtime security strategies.
Mr. Noh emphasized, "The most crucial element in flexible cloud operations, which is at the core of the cloud, is the ‘container.’ However, containers lack visibility into open-source components and have undiscovered vulnerabilities. They are also at risk of being disabled through DoS (Denial of Service) attacks. To enhance container security, an SBOM is needed for systematic open-source management in addition to existing kernel security."
He added, "Security risks that cannot be mitigated during the development and supply chain stages should be addressed through runtime security. Runtime security creates a safer environment through real-time monitoring and control in the latest container environments. Additionally, eBPF is essential for applying security safely without the blue screen of death (BSOD) issues, while allowing strong central control of security modules. However, eBPF should be applied in various ways to meet security requirements."

Photo 15. Young-Jin Roh, Head of Cloud R&D Division at AhnLab, emphasized the need for SBOM and runtime security to create a secure container environment.
Jae Hoon Hwang, General Manager of Convergence Product & Service Planning Team at AhnLab, gave a presentation on the topic of "Continuous Puzzle Games in CPS World." He introduced various security issues and trends in the CPS environment and shared AhnLab's response strategies.
According to Mr. Hwang, the CPS environment involves many technologies and devices intertwined like puzzle pieces, meaning security vulnerabilities are very diverse and the capacity to respond to them is still insufficient. Moreover, the security risks have been further exacerbated recently as threat actors increasingly target both IT and OT environments and use AI technology in their attacks.
Mr. Hwang mentioned that CPS security should be considered in terms of ▲visibility, ▲detection, and ▲response. AhnLab also currently supports all 3 aspects.
Mr. Hwang stated, "The best way to effectively achieve visibility in a CPS environment without affecting operations is to analyze based on network traffic. This is because assets can be identified as long as packets are collected, even without installing a separate agent. In addition, conducting endpoint-based identification can provide enhanced visibility. By using endpoint hardening for CPS security assets to control processes, removable devices, and network communications based on a pre-registered allowlist, assets can be effectively protected from new and changing threats such as ransomware and APT attacks."

Photo 16. Jae Hoon Hwang, General Manager of the Convergence Product & Service Planning Team at AhnLab, introduced methods to counter advanced security threats in CPS environments.
After all the presentation sessions ended, AhnLab held a prize draw, further heightening the lively atmosphere of the event. In addition, demonstration booths were set up in the event lobby, allowing attendees to directly experience global strategic products and services from AhnLab and its subsidiaries. Participants who visited the booth were also offered tailored consultations for the effective implementation of AhnLab's security solutions.

Photo 17. Demonstration of products at the demo booth in the event lobby (1)

Photo 18. Demonstration of products at the demo booth in the event lobby (2)
Conclusion
Celebrating its 16th year, AhnLab ISF 2024 was a platform for sharing security insights with numerous participants, centered around the keywords of AI and unified security. AhnLab has emphasized the importance of unification for 16 years and plans to enhance new technologies like AI and its platform to contribute to improving customer business productivity. Since no single company can address all cyber threats alone as mentioned at the beginning of this post, AhnLab hopes that more companies and institutions will cooperate to respond to evolving threats.