Back Mk.Co.Kr An artificial intelligence (AI)-based public interest security project analyzed all of the standard ..
An artificial intelligence (AI)-based public interest security project analyzed all of the standard software of e-government in Korea and found 990 security vulnerabilities. In addition, it plans to establish a collaboration system that not only detects vulnerabilities but also connects actual security patches and supply chain propagation.
On the 14th, Project Plasma unveiled the first analysis results of the public interest AI security initiative 'Project Canopy'. The first target of analysis is the common component of the e-Government Standard Framework (eGovFrame), which is widely used in government, public institutions, and system integration (SI) projects.
Project Canopy detected more than 1,300 vulnerability candidates with an AI-based automation analysis engine and removed duplication and false positives to finally identify 990 structural defects and security vulnerabilities. Of these, 10% were classified as "critical" or "high."
Major vulnerabilities included authentication bypass to log in without a password, SQL execution to arbitrarily manipulate databases, file theft due to encryption key exposure, and unsafe direct object reference (IDOR·BOLA) that can be attacked.
Project Canopy also pointed out the structural characteristics of the e-government standard framework as an issue. It is not a structure that allows simple updates like an external library, but a method of copying and using source code, so it is easy to cause a "patch isolation" phenomenon in which security patches are not delivered to actual operating systems.
Project Canopy emphasized that the results are not raw results generated by the Large Language Model (LLM), but refined data that filters out the possibility of false positives through its own analysis engine. AI automatically analyzed vast amounts of code that humans have to check for months to select candidates for vulnerabilities that can be exploited.
Project Canopy plans to focus on detecting vulnerabilities as well as establishing a collaborative system for verification and patch propagation. More than 300 security patches have been completed so far, and in addition to the e-government standard framework, major open-source software at and abroad will be regularly analyzed.
Park Se-joon, chairman of the project Canopy, said, "Companies and institutions that operate e-government standard framework-based systems need to take security measures by referring to the results of this analysis. We will build a safe ecosystem across the public software supply chain beyond detection of vulnerabilities."
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
