Breaking
KRLarge-scale progressive and conservative gatherings in downtown Seoul on National Foundation Day... traffic congestionINVilnius Airport Closed After Possible Drone Spotted Near Belarus BorderITAirspace violation in returned Lithuania and drone attacks in UkraineARUAE Attorney General: Investigations reveal that a co-pilot attempted to carry out a terrorist operationES11 injured when a bar collapses in San Vicente de la SonsierraAUTornado damages homes and causes power outages on New South Wales south coastTRIntervention in Energy Markets from G7: 100 Million Barrels of Oil Will Be ReleasedTRExecution Attempt of Christa Pike Failed in TennesseeCNPakistani troops expected to take over defensive functions for Saudi ArabiaTRLocal navigation move from Türkiye: Bilisim Vadisi announcedKRLarge-scale progressive and conservative gatherings in downtown Seoul on National Foundation Day... traffic congestionINVilnius Airport Closed After Possible Drone Spotted Near Belarus BorderITAirspace violation in returned Lithuania and drone attacks in UkraineARUAE Attorney General: Investigations reveal that a co-pilot attempted to carry out a terrorist operationES11 injured when a bar collapses in San Vicente de la SonsierraAUTornado damages homes and causes power outages on New South Wales south coastTRIntervention in Energy Markets from G7: 100 Million Barrels of Oil Will Be ReleasedTRExecution Attempt of Christa Pike Failed in TennesseeCNPakistani troops expected to take over defensive functions for Saudi ArabiaTRLocal navigation move from Türkiye: Bilisim Vadisi announced
BackGovernment to strengthen cyber defense of critical infrastructure, sharing hidden threat investigation methods from FY2017
Government to strengthen cyber defense of critical infrastructure, sharing hidden threat investigation methods from FY2017
Developing
時事通信49 minutes agoTech1 min readJapanView original

Government to strengthen cyber defense of critical infrastructure, sharing hidden threat investigation methods from FY2017

Quick Look

  • In FY2027, the government will strengthen the creation of detection methods and information sharing for ``threat hunting,'' which investigates intrusions and hiding situations between the public and private sectors, in order to protect critical infrastructure such as electricity and communications from cyberattacks.
  • The aim is to prevent infrastructure outages in emergencies.

AI-generated summary

Why It Matters

A law related to active cyber defense came into effect on the 1st. There are concerns about hidden attacks on critical infrastructure.

Font size

In fiscal 2027, the government will strengthen public-private efforts to investigate whether attackers have infiltrated or hidden within systems in order to protect critical infrastructure such as electricity and communications from cyberattacks. Build detection methods according to threat information and share them with private businesses. Preventing crises caused by emergency infrastructure outages.

Promoting the development of specialized AI Digital Minister Furukawa ``Data is the name of the game'' - Interview with new ministers

"Threat hunting," which detects threats hidden within systems, is one of the active cyber defense methods for which related laws came into effect on the 1st. Based on specific threat information, the National Cyber ​​Control Office (NCO) will reproduce attacks in a virtual environment and build and verify detection methods that can be used in the private sector.

The Ministry of Defense will also utilize the search capabilities it has cultivated through the Self-Defense Forces' information systems to provide direct support by visiting critical infrastructure operators upon request. The NCO and the Ministry of Defense included related expenses in their budget request for fiscal year 2027.

The reason behind this is that the outage of critical private infrastructure could lead to a national crisis in an emergency. In 2024, U.S. authorities estimated that Bolt Typhoon, a group believed to be backed by the Chinese government, had maintained access to some critical U.S. infrastructure for more than five years. It is believed that the attacker exploited legitimate management tools to evade detection and hide in a way that would allow him to shut down the infrastructure in an emergency.

On the other hand, accumulating and analyzing the logs necessary for searching requires manpower and costs. NTT Data has been conducting threat hunting using its internal system since 2024. In order to respond to latent attacks, we formulate a hypothesis that a specific attack may be occurring even when there is no warning, and search for suspicious activity from logs. Yukio Nakajima, who is in charge of the project, pointed out, ``In order to expand our activities, we need to demonstrate cost-effectiveness to management.''

NCO officials explain that preparing for latent attacks alone is unlikely to lead to investment decisions by management. He says that even ransomware, which is a familiar threat, has common techniques such as searching inside the system after intrusion, and emphasizes the significance of ``threat hunting as a countermeasure against ransomware.''

What to Watch

AI outlook — possibilities, not facts

  • Related expenses will be included in the budget request for FY2017.

    Very likely · Within months

Open Questions

  • How much are the specific related expenses in the FY2017 budget?
  • What will be the specific framework for support for private businesses?

Related Topics

This article was originally published by 時事通信.

Related Stories

Ministry of Health, Labor and Welfare to support implementation of cloud-based electronic medical records, considering security certification system and subsidies
Developing·

Ministry of Health, Labor and Welfare to support implementation of cloud-based electronic medical records, considering security certification system and subsidies

The Ministry of Health, Labor and Welfare has established a system to certify excellent cyber-attack countermeasure systems within this fiscal year in order to popularize ``cloud-type'' electronic medical records that manage medical information on the Internet, and has decided to provide financial assistance for the introduction of such systems to medical institutions as early as 2027.

時事通信
2 min read
Moonstar announces possibility of customer information leak due to unauthorized access to system server
Developing·

Moonstar announces possibility of customer information leak due to unauthorized access to system server

Shoe manufacturer Moonstar announced on October 2 that the names, addresses, phone numbers, email addresses, and past order information of online store users may have been leaked due to unauthorized external access to its system server. This is a follow-up to the suspected unauthorized access announced on March 26th, and an internal investigation revealed the possibility of unauthorized login and information acquisition. Phishing emails were also confirmed to be sent, and countermeasures were taken, including blocking external connections to the server and forcing password changes. Credit card numbers and passwords are not stored on the relevant server.

ITmedia
2 min read
Abba House International announces possible customer information leak due to unauthorized access
Developing·

Abba House International announces possible customer information leak due to unauthorized access

On October 2, Abba House International announced that customers' personal information may have been leaked due to unauthorized access to its internal systems by a third party. On September 28th, multiple customers contacted us about a suspicious refund notification email that matched their order information, and this was discovered as a result of an investigation. Information that may be leaked includes member IDs, names, addresses, phone numbers, email addresses, dates of birth, gender, and order information, and may even affect customers who have withdrawn from membership. Credit card information is managed by the payment processing company's system, and no leaks have been confirmed.

ITmedia
2 min read
Softbank successfully conducts experiment to provide communication during disasters using large unmanned aircraft
Developing·

Softbank successfully conducts experiment to provide communication during disasters using large unmanned aircraft

SoftBank has successfully conducted a demonstration experiment in which a large unmanned aircraft is equipped with a communications pod for disaster response, and it sends out radio waves from 3,000 meters above the ground to create a communications area over 5 kilometers in diameter. This was the first attempt in Japan to use GA-ASI's MQ-9B, and confirmed communication quality of up to 20 Mbps downlink, marking a step toward social implementation as emergency communication infrastructure during disasters.

ITmedia
3 min read
The government begins operating active cyber defense, and the police and Self-Defense Forces infiltrate the attack server and render it harmless
Developing·

The government begins operating active cyber defense, and the police and Self-Defense Forces infiltrate the attack server and render it harmless

With the enforcement of the Act on Strengthening Cyber Response Capabilities, the government has begun operating active cyber defense. When the police or Self-Defense Forces detect signs of an attack, they infiltrate the other party's server and render it harmless by erasing the malicious program. Public-private collaboration will also be strengthened, and the use of communications information will come into effect from fall 2027.

時事通信
2 min read
More on this topiccyber attack