KA-SAT 침해사고는 위성 통신 보안이 위성뿐 아니라 지상 관리망, 게이트웨이, 사용자 단말을 포함한 종단 간 시스템의 문제임을 보여주었습니다.
5G NTN은 위성을 5G 표준에 통합하고 있는 과정에 있으며, 6G NTN은 재생형 탑재체, 위성 간 링크, 다계층 네트워크를 통해 더욱 유연한 연결을 지향합니다.
위 사건과 변화하는 구조에 따라 신뢰 경계, 분산된 관측 지점, 전체 수명주기를 고려한 체계적인 위협 모델링이 필요합니다.

A Network Without Borders, Threats Across Layers: Redefining Security for 5G/6G Non-Terrestrial Networks (NTN)
The KA-SAT incident demonstrated that satellite communication security is an end-to-end challenge spanning not just the space segment, but ground management networks, gateways, and user terminals as well.
While 5G Non-Terrestrial Networks (NTN) are actively integrating satellites into standard 5G frameworks, 6G NTN aims to deliver greater architectural flexibility via regenerative payloads, inter-satellite links (ISLs), and multi-layered networks.
In light of this incident and the evolving topology, systematic threat modeling must be established to account for dynamic trust boundaries, distributed observation points, and the complete system lifecycle.
Recently, large language models (LLMs) have been expanding beyond simple question-answering into AI agents that judge their next action based on goals and context and make use of external tools. Our research team is also conducting research using AI agents, and in this series we’ll introduce the basic concepts of AI agents as well as the structure and key functions of the AI agent our team is developing. This first installment focuses on the theme “What Is an AI Agent?” and looks at the concept of AI agents and how they generally operate.
최근 대규모 언어 모델(LLM)은 단순한 질의응답을 넘어, 목표와 상황에 따라 다음 행동을 판단하고 외부 도구를 활용하는 AI 에이전트로 확장되고 있습니다. 우리 연구팀도 AI 에이전트를 활용한 연구를 진행하고 있으며, 이번 시리즈에서는 AI 에이전트의 기본 개념부터 연구팀이 개발하고 있는 AI 에이전트의 구조와 주요 기능을 소개합니다. 본 1편에서는 ‘AI 에이전트란 무엇인가’를 주제로, AI 에이전트의 개념과 일반적인 동작 방식을 살펴봅니다.
AI model optimization is not simply a matter of making a model smaller — it is the process of reducing costs such as memory, processing time, computation, and power consumption while maintaining the quality required in the actual runtime environment. Representative methods include quantization, pruning, knowledge distillation, and efficient architecture design. That said, reductions in parameter count or computation do not automatically translate into lower real-world costs, so the results must be verified directly on the target device and execution engine. Ultimately, the key is to tune the techniques — and how strongly they are applied — to the characteristics of the model and its modules, and to confirm that the final system meets both the quality and cost criteria.
AI 모델 경량화는 단순히 모델 크기를 줄이는 것이 아니라, 실제 실행 환경에서 요구되는 품질을 유지하면서 메모리, 처리 시간, 연산량, 전력 소모 등의 비용을 줄이는 최적화 과정이다. 대표적인 방법으로는 양자화, 프루닝, 지식 증류, 효율적인 구조 설계가 있다. 다만 파라미터 수나 연산량 감소가 실제 비용 감소로 곧바로 이어지는 것은 아니므로 목표 기기와 실행 엔진에서 직접 검증해야 한다. 결국 모델과 모듈의 특성에 맞게 기법과 적용 수준을 조정하고, 최종 시스템이 품질과 비용 기준을 함께 만족하는지를 확인하는 것이 핵심이다.

[CCT (Cyber Crime Tracker) ②] The Eyes That Track Cybercrime: A Step-by-Step Data Collection and Analysis Pipeline
Malicious websites rarely exist in isolation; instead, they form interconnected networks known as ‘cybercrime ecosystems,’ where a single organization manages various illicit sites simultaneously. In Part 1, we examined this ecosystem and introduced the CCT (Cyber Crime Tracker) framework as a necessary tool to combat these threats.
In Part 2 of this series, we will dive into the step-by-step technical process of uncovering the connections between these sites—starting from data collection, the ‘tracking eyes’ of the CCT framework, all the way to the final analysis.
유해사이트들은 단일 사이트로 존재하기보다 서로 연결된 네트워크 형태로 결합되어, 하나의 운영 조직이 여러 유형을 병렬적으로 관리하는 이른바 ‘사이버범죄 생태계’를 이루고 있습니다. 지난 1편에서는 이러한 생태계의 특징을 파악하고, 위협에 효과적으로 대응하기 위한 CCT(Cyber Crime Tracker) 프레임워크의 필요성을 살펴보았습니다.
시리즈로 이어지는 본 2편에서는 CCT 프레임워크의 첫 단추이자 ‘추적하는 눈’이라 할 수 있는 데이터 수집부터 최종 분석에 이르기까지, 사이트 간 연관성을 기술적으로 추적하는 단계별 과정을 구체적으로 소개하고자 합니다.

LLM & RAG based Cyber Threat Prediction Part. 3 (Technical Vision of the T9 Project with an Integrated Prediction Pipeline)
In Parts 1 and 2, we explored the concept of LLM and RAG-based cyber threat prediction and examined methods for enhancing LLM prediction accuracy by integrating XAI. Building upon those discussions, this article introduces the comprehensive LLM pipeline that leverages XAI-integrated RAG to forecast potential future cyber threats. In particular, we illustrate the integration framework of T9 Detect, which moves beyond single-log-centric defense to organically understand data flows, and T9 Predict, which reliably forecasts subsequent attack sequences based on those insights, thereby presenting a technical vision for a proactive security response architecture.
앞선 1탄과 2탄에서는 LLM 및 RAG 기반 사이버 위협 예측의 개념을 살펴보고, XAI를 결합하여 LLM의 예측 정확도를 높이는 방법에 대해 알아보았습니다. 본 글에서는 이러한 내용을 바탕으로, XAI가 결합된 RAG를 활용하여 향후 출현 가능한 사이버 위협을 예측하는 LLM의 전체 파이프라인을 소개합니다. 특히 단일 로그 중심의 방어를 넘어 데이터 흐름을 유기적으로 이해하는 T9 Detect와, 이를 기반으로 차단계 공격 흐름을 신뢰성 있게 전망하는 T9 Predict의 결합 구조를 설명하며 능동형 보안 대응 체계의 기술적 비전을 제시합니다.

