AI Automated Translation.

Font Size

Share

Tving faces data breach, reconstructs security based on Zero Trust

Tving faces data breach, reconstructs security based on Zero Trust

On the 23rd, domestic OTT (over-the-top video streaming service) Tving announced that it is making every effort to strengthen security and protect customer information by rebuilding its security system based on Zero Trust following a personal information infringement incident.

Zero Trust is a security principle that does not trust any access by default and continuously verifies users, devices, permissions, and other factors. Tving has established four core principles: thorough access verification, least privilege, assumption of breach, and continuous validation, and is applying them across its services and cloud environments.

To implement "thorough access verification," the company has applied authentication token verification across all app and web segments and enforced mandatory updates for older versions of apps. It is also considering the application of detection and blocking technologies for tampered apps. In line with the "least privilege" principle, Tving is strengthening its access control system by segmenting access permissions to systems and services by job function and systematically managing the scope and validity period of those permissions.

Additionally, based on the "assumption of breach," the company is reviewing incident response frameworks for each scenario and refining response procedures. To ensure "continuous validation," it has established a system that detects abnormal behavior in cloud environments in real time and sends alerts when unauthorized access occurs.

Tving is also pursuing follow-up measures to continuously enhance its Zero Trust-based security system. It is validating the introduction of credential management tools and source code analysis and vulnerability management solutions, and plans to expand the scope of penetration testing and vulnerability diagnosis to include cloud accounts and permission domains. The company is also working on enhancing scenario-based incident response frameworks and considering the adoption of bug bounty programs.

Separately, Tving is accelerating the establishment of a next-generation security relationship system. It will strengthen its integrated cloud security inspection framework and apply AI-based security threat detection and blocking technologies to continuously improve its real-time response capabilities against security threats.

Alongside measures based on Zero Trust principles, Tving has also strengthened key security areas. Secret information within code has been transferred to a dedicated management system, an automatic blocking and abnormal access detection system at the source code storage stage has been established, and next-generation endpoint security solutions (EDR) have been applied to all employees' PCs.

In addition, to protect customer information, Tving is replacing app signing keys and digital rights management (DRM) keys entirely and strengthening its security system for verifying login and connection status. The company is also changing its password storage method to a bcrypt-based approach to further elevate the level of customer information protection.

A Tving official stated, "We are prioritizing the protection of customer information by continuously reviewing our security systems and implementing actual measures to strengthen security levels." They added, "We will continue to enhance access and permission management and breach response systems based on Zero Trust principles, invest in next-generation security technologies such as AI-based threat detection, and build a safer service environment."

"Please note that this article has been automatically translated by AI, and minor discrepancies from the original text may occur due to machine translation limits."