EASYCERTI Jeonghyeon Kwon Director
This session examines the limitations of traditional rule- and threshold-based security monitoring using business system logs, focusing on insider threats, false positives, and alert fatigue. It covers the need to transition to AI-based detection and introduces strategies for learning normal access patterns through machine learning techniques to identify abnormal access, large-scale data exfiltration, and attempted privilege or account takeover. It also explains how sLLMs can be integrated to analyze the context and intent behind detection results in natural language, while presenting practical operational approaches using lightweight CPU-based models and on-premises environments.
Korean
English
Chinese
Japanese


