Mecletter April | How can we protect cloud security in the era of generative AI?
Date of creation : 2024-04-24

Hello, dear readers of the Meckletter!
Greetings in the last week of April, as the greenery deepens. 🌳
We continue to share stories related to AI in the Meckletter. The topics we have covered so far are still relevant. The AI market is continuously evolving, and corporate clients are accelerating the adoption of AI. (View past newsletters)
However, to truly reap the benefits of AI innovation, there is a critical issue that must be addressed: ‘security’. In this issue, we will explore security in the AI era with cloud security experts.
Don’t miss the security checklist prepared for corporate clients in the main text.😉

Cloud Security in the Era of Generative AI
The Hidden Danger of Shadow AI
With the advancement of generative AI, many people can now enjoy high-level technology without professional development knowledge. However, as the utilization of AI in our daily lives has increased, the security threats posed by ‘users (employees)’ have also significantly increased.
You may all be familiar with the term shadow IT, which refers to the use of unauthorized IT resources within an organization. Since the rise of AI, the term ‘shadow AI’ has emerged. Following the release of ChatGPT, there has been an explosive increase in various versions of generative AI tools, which has heightened the risk of an expanded attack surface due to the use of generative AI tools without the knowledge of the IT department or IT administrators. In fact, according to a Gartner survey, 41% of employees acquired technology beyond the control of the IT department in 2022, and this figure is expected to rise to 75% by 2027.
Anyone Can Be a Hacker? The Threat of Attackers
The advantage of generative AI, which allows anyone to easily create expert-level content, also poses a lethal threat: with just the injection of vulnerable code, anyone can easily hack. The technical barriers to attacks that were previously attempted only by a small number of professional hackers have been lowered.
In particular, the security threats posed by WormGPT are a serious issue; attackers can train WormGPT with hacking manuals, malware samples, etc., to generate malware and carry out email attacks, hacking, DDoS attacks, and more. In fact, on the dark web, posts about hacking methods using WormGPT are actively shared, and research shows that phishing email security threats increased by 1,265% in the year following the announcement of ChatGPT.

Security Strategies in the Era of Generative AI
As cyber threats exploiting AI continue to increase, companies must implement mechanisms to mitigate security vulnerabilities and minimize the risk of incidents. At this time, it is important to establish a response system according to the types of cyber threats mentioned earlier.
First, to address 'user threats', companies should establish security policy standards that include authentication, access control, encryption, and data protection to prevent sensitive data or personal information from being exposed. It is also necessary to conduct regular training for users to prepare for APT attacks such as social engineering attacks or email phishing.
Furthermore, to respond to the increasingly sophisticated AI-based 'attacker threats', it is essential to build the following two types of systems:
Establish data collection and analysis tools that can respond to various threats and vulnerabilities: Network traffic, logs, and events generated from service workloads should be collected and analyzed in real-time to quickly detect and respond to abnormal behavior patterns, malware, and malicious network traffic.
Establish infrastructure security systems: To address threats that may arise through various paths such as networks, systems, data, and user domains, infrastructure security systems such as firewalls, intrusion detection systems, encryption, access control, and monitoring systems must be in place.
📝 Security Checklist for Corporate Clients
The security threat landscape in the era of generative AI we have examined so far can be summarized with the keywords #Increase in Attack Surface #Intelligence of Attack Techniques. Rather than the emergence of entirely new types of security threats, it is evident that existing security threats have become much more widespread and intricate.
Under these threats, companies need to assess their security vulnerabilities and build appropriate solutions to address them. We at Meclutter have prepared a security checklist that allows for a simple review of this. Download the checklist consisting of a total of 7 items and check the level of security vulnerabilities in our company.
If you have any questions about the security checklist or need additional explanations regarding the inspection results, please leave an inquiry with Megazone Cloud. A cloud security expert will respond quickly.
👉Consult with a Cloud Security Expert

Can Amazon Security Lake Reduce AI-Based Security Threats?
With the advancement of generative AI and the increasingly sophisticated cyber security threats, companies need a system that can technically respond to these threats to protect themselves. In particular, a platform that can analyze and respond to large volumes of logs and event data in real-time based on AI is essential. The representative solution for this is Amazon Security Lake.
From the perspective of security compliance and governance, the most challenging aspect for corporate clients is building a system for incident prevention and response, as well as establishing a monitoring environment. Through Amazon Security Lake, clients can internalize a system that allows them to respond to security threats without the help of external experts. Check out how Amazon Security Lake can assist in strengthening corporate security in the full article.

🌎Go Global🌎
Are you interested in expanding overseas?
Let's also read about the trends in the global IT market!
This article introduces a case where Japan has addressed the labor shortage issue in the agriculture and livestock industry by adopting IT/cloud technology.
In light of the upcoming Labor Day on May 1st, we will look into the introduction of AI and the changes in the Vietnamese labor market.
Starting from 2024, Korean companies entering Vietnam may have to pay higher corporate taxes than before; check out the specific details.
You can continuously scan the vulnerabilities of container images using Amazon Inspector for container security.
👉For inquiries about global expansion, contact us here!
Vietnam: ask_vietnam@megazone.com
Japan: gojapan@megazone.com
