Biz/Finance
 
    
  
+Login    +Register    +Find Id / Pw Home  l  Archives  l  Learning Times  |  Sitemap  |  Subscription  l  Media Kit  l  PDF
    Home > Newszone > Biz/Finance >
  National
  Biz/Finance
    Photo News  
    Meet The CEO  
    Rediscovering Korean History  
    G-20  
    Best Global Brands in Korea  
    Korea: From Rags to Riches  
    New Global Reality  
    Global IRs  
    Global Brand of Korea  
    Green Finance  
    Expat Banking  
    The Rise and Fall of Business Empires  
    Economic Essay Contest  
    Industry Report  
    Business Report  
    Financial Report  
    Premium Brands  
    Stock Market Watch  
  BusinessFocus
  Technology
  Arts & Living
  Sports
  Opinion
  Community
  Special
  Science
  The Learning Times
     About English News
     iBT TOEFL
     Essay
     
 
   07-12-2009 18:15 여성 음성 남성 음성 News List
Korea Ill-Prepared for Online Attacks

By Kim Tong-hyung
Staff Reporter

South Korea has so big a hole in its cyber security that another wave of online attacks will prove to be as devastating as those of last week.

First, virtually anybody can mount such attacks. Although government officials suspect North Korea may have been orchestrating these virtual attacks, a gang of teenagers could possibly organize and bring the same amount of damage as a nation can, and with a program purchased online for the same price as a song.

When the country was pummeled by a massive distributed denial of service (DDoS) attack over four days until last weekend, it was a handful of private firms that came to the rescue.

In addition, systemic flaws such as over-reliance on Microsoft's Active-X program need to be addressed. Without them, all Korea can do appears to be nothing but pray that no such attacks recur.

The Korea Communications Commission (KCC) admits that more DDoS attacks are a possibility, considering that the types of malicious software that infected scores of Korean computers at homes and offices are programmed to update automatically. Whether the country would be better prepared for another powerful Internet attack is a totally different matter.

``We have been analyzing the malicious codes, and found that the programs were designed to self-destruct after initiating three attacks. We have yet to find a mutated version of the codes,'' said Hwang Cheol-joong, a KCC official.

As of Saturday, more than 97 percent of 77,875 infected computers had been cleared of the malicious programs, the KCC said. The state-run Korea Information Security Agency (KISA) is currently analyzing 22 sample types of the malicious codes.

``It is encouraging that the number of infected computers was fewer than first thought, even when considering the devices that remain unreported. However, considering that these DDoS bots are not controlled by command and control (C&C) operational software, but programmed for automated updates and self-destruction, we need to stay alert. There also might be types of codes that we have yet to discover,'' Hwang said.

AhnLab in particular had a crucial role in containing the attacks, being the first to discover that the malicious codes were designed to overwrite and destroy data on hard drives. Despite the warning, the KCC, looking somewhat clueless, needed an extra day to issue a warning.

AhnLab was also the first to identify the timing of the third attack and that the malicious codes had changed their targets, while also listing the Internet protocol (IP) addresses of the programs' hosting sites around the world. The KCC failed to confirm the report until the third attack was carried out at 6 p.m. last Thursday, just as AhnLab predicted.

According to industry figures, the country's top five computer vaccine developers averaged less than 5 billion won (about $3.9 million) in operating profit last year. AhnLab, the top company, posted 9.7 billion, followed by Hauri's 2.7 billion won, but Inca Internet suffered 2.3 billion won in losses.

The companies combine to hire about 1,000 security personnel, with about 500 of them considered as ``experienced experts.'' They have little backing from government organizations when massive cyber attacks occur, as seen from the recent case, or the ``great disruption'' of 2003, when the country's computers were crippled by a DDoS attack initiated by SQL slammer worms. In contrast, 695 government organizations hired an average of 0.7 security experts, with nearly 68 percent of them employing none.

The National Intelligence Service (NIS), the country's spy agency, is responsible for protecting public Internet infrastructure from Internet attacks, while KCC and KISA handle the private side.

However, the Ministry of Public Administration and Security deals with breaches within government networks, while the National Police Agency combats ``cyber crimes.''

The complicated relations between these agencies make it difficult for the government to muster a quick and coordinated approach when crisis hits, according to critics, who call for the establishment of a ``control tower.''

``We agree that there should be a more simplified chain of command. The current system has problems,'' Choi See-joong, the KCC chairman, told reporters last week.

It could also be said that Korea was behind for its Microsoft monoculture for Web browsers. In Korea, all encrypted transactions on the Internet are required to be done through Microsoft's ``Active-X'' controls, which work only on Internet Explorer browsers. As a result, the market share of Internet Explorer remains in the high 90s.

However, Active-X is also linked with security concerns, as the controls require full access to the Windows operating system on computers. This means that malicious programs can direct the browser to download files that compromise the user's control of the computer.

``Active-X happens to be one of the ideal tools for malicious codes to be distributed. Even Microsoft is phasing Active-X out due to security worries, but Korea has been a step behind,'' said an official from KTB Solutions, a computer software company.

thkim@koreatimes.co.kr





한국과 일본 국가부도위험 비슷해졌다

이동국 포함 '최강희號 1기' 출범

안철수 자발적 지지모임 '나철수' 창립

EADS, KF-X사업 20% 투자 계획 철회

작전명 ‘대담한 악어”: 美, 北·中 겨냥 대규모 해상 훈련

서울시, 대형마트·SSM 영업시간 제한 추진

"정부·기업 신뢰도 크게 떨어져"

7000m 심해서 괴물새우 발견

국적항공기 조종실 불시점검 강화

KB국민은행 노조, '사외이사 추천 방해' 경영진 고발


 
 
Japan’s sovereign risks on par wi..
Filipino flight attendants caught..
Lee Dong-gook earns another call-..
Volleyball match fixing widens to..
Surprise addition
Koreans negative on opposition’s ..
Civic groups back activist retwee..
Novelist Gong Ji-young taking Twi..
Delivery services for miniature c..
Korea goes local for World Cup qu..
Do-Nothing Congress
European currency solution
Members of K-pop group Girls’ Generation pose at the studio ...