WhiteMail

Security glossary

Key email & general security terms in one place. Tap any item for the CEO/CISO takeaway.

Attack types

피싱 (Phishing)

A deceptive message impersonating a trusted party to steal credentials, money, or sensitive data.

For executives (CEO·CISO)

Most breaches start with a single email, yet many orgs over-trust the spam filter. Technical detection and user training each fail alone. Commonly missed: without a report button and a triage process behind it, a suspicious employee has nowhere to act — build the report→triage→feedback loop.

Read more
스피어 피싱 (Spear phishing)

Targeted phishing tailored to a specific person or organization using researched details.

For executives (CEO·CISO)

A small set of high-privilege people (execs, finance, HR) are the targets, so org-average detection metrics hide the real risk. Attackers enrich context from public web/SNS data. Commonly missed: pair a dedicated protection policy for VIP/finance roles with minimizing exposed exec details (emails, titles).

Read more
비즈니스 이메일 침해BEC

Social-engineering fraud impersonating execs/vendors to trigger wires or data leaks — often with no link or attachment.

For executives (CEO·CISO)

The single largest financial-loss vector (tens of thousands to millions per incident). With no malware, AV/sandbox are useless and human process is the last line. Commonly missed: tech alone cannot stop it — hard-code dual-channel approval for payments/bank-detail changes above a threshold, and train staff that "urgent & confidential" is itself a red flag.

Read more
공급망 이메일 침해VEC

A supply-chain BEC where a trusted vendor's account is hijacked to swap payment details on invoices.

For executives (CEO·CISO)

Even with perfect internal security, a breached vendor sends forged invoices from the real account, often slipping into an existing thread. Commonly missed: verify any bank-detail change by calling a pre-registered number (never by email reply), and keep an audit trail of vendor payment-detail changes.

Read more
큐싱 (Quishing)

Phishing that hides a malicious link behind a QR code to bypass URL filters.

For executives (CEO·CISO)

A QR is an image, so URL/link scanners pass it straight through — and users scan with a less-protected personal phone, outside corporate controls. Commonly missed: confirm your solution actually decodes the QR image and inspects the URL inside it (many products do not).

Read more
스미싱 / 비싱 (Smishing / Vishing)

Phishing via SMS (smishing) or voice calls (vishing), often combined with email attacks.

For executives (CEO·CISO)

Attacks cross channels (email → SMS → a trust-building call); defending email alone gets bypassed. Commonly missed: weak identity checks at the help desk/call center let one phone call reset a password or MFA — harden human-facing social-engineering procedures.

Read more
스푸핑 (Spoofing)

Forging the sender address or display name to appear as a legitimate sender.

For executives (CEO·CISO)

When your domain is spoofed, customers/partners get hurt and the blame lands on your brand; with no defense, anyone can send as you. Commonly missed: many leave DMARC at monitor (p=none) forever — step the policy up to enforcing (p=reject) so it actually blocks.

Read more
표시이름 사칭 (Display-name spoofing)

Faking only the display name (e.g., an exec or brand) while the real address differs.

For executives (CEO·CISO)

DMARC won't stop it — the real domain is fine and only the display name is faked, and it's especially convincing on mobile where the address is hidden. Commonly missed: don't rely on auth (SPF/DKIM/DMARC) alone — verify your solution detects display names impersonating execs/brands.

Read more
유사 도메인 (Lookalike / Homoglyph)

A near-identical impostor domain (e.g., rn vs m, 0 vs o) used to fool the eye.

For executives (CEO·CISO)

Nearly indistinguishable by eye, and attackers register the domain just before use to dodge reputation blocks. Commonly missed: after-the-fact detection is too late — run a process to proactively monitor, register, and take down lookalikes of your brand.

Read more
계정 탈취ATO

Seizing a real account with stolen credentials to attack from the inside.

For executives (CEO·CISO)

Mail now comes from a real account, so it passes auth and reputation, then spreads internally and into VEC — the most dangerous "trusted sender" attack. Commonly missed: beyond login protection (MFA), detect post-takeover anomalies (impossible travel, mass sends, new auto-forward rules).

Read more
자격증명 탈취 (Credential harvesting)

Collecting usernames/passwords, typically via fake login pages.

For executives (CEO·CISO)

If staff reuse passwords across work and personal sites, a leak anywhere becomes the key to your accounts. Commonly missed: password policy is not enough — mandate MFA org-wide and monitor dark-web credential dumps to pre-emptively lock already-exposed accounts.

Read more
제로데이 (Zero-day)

A brand-new vulnerability or attack with no patch or signature yet.

For executives (CEO·CISO)

By definition signatures/reputation cannot catch it — defenses that only block "known bad" become the first victim. Commonly missed: combine behavior/context-based detection for the unknown with fast patch operations that shrink the exposure window.

Read more
AI 생성 피싱 (AI-Generated Phishing)

An attack that uses large language models to mass-produce highly natural, personalized phishing emails free of grammatical errors.

앵글러 피싱 (Angler Phishing)

A phishing technique using fake customer-support accounts on social media to approach complaining users and steal their information.

베이팅 (Baiting)

A technique that lures victims into running malware themselves using enticing bait such as infected USB drives or free downloads.

브랜드 사칭 (Brand Impersonation)

A technique that mimics a well-known brand's logo, design, and domain to deceive users with emails or sites that look authentic.

CEO 사기 (CEO Fraud)

A common BEC variant in which an attacker impersonates a CEO or top executive to instruct finance staff to make urgent wire transfers.

클론 피싱 (Clone Phishing)

A phishing technique that copies a legitimate previously delivered email and resends it with attachments or links swapped for malicious ones.

동의 피싱 (Consent Phishing)

A phishing technique that tricks users into granting permissions to a malicious OAuth app, enabling data access without stealing passwords.

대화 가로채기 (Conversation Hijacking)

An attack where adversaries monitor an ongoing business email conversation and inject themselves to alter payment details or commit fraud.

딥페이크 피싱 (Deepfake Phishing)

An attack using AI-generated fake audio or video to impersonate executives in calls or voice messages to induce wire transfers or data leaks.

이메일 계정 탈취 (Email Account Takeover)ATO

An attack where adversaries steal credentials to seize a legitimate email account and abuse it for internal impersonation or fraud.

기프트카드 사기 (Gift Card Scam)

A common BEC social-engineering scam that impersonates an executive to urgently ask an employee to buy gift cards and send the codes.

호모그래프 공격 (Homograph Attack)IDN homograph

An attack using visually identical Unicode characters (e.g., Cyrillic 'a' vs Latin 'a') to create fraudulent domains that look legitimate.

사칭 공격 (Impersonation Attack)

A general class of attacks that masquerade as trusted persons, brands, or organizations so victims believe requests are legitimate.

송장 사기 (Invoice Fraud)

A BEC-style financial fraud that sends fake or altered invoices to redirect payments to attacker-controlled accounts.

악성 첨부파일 (Malicious Attachment)

An attack vector delivering malware or malicious macros hidden in email attachments such as documents or archives that infect upon opening.

악성 스팸 (Malspam)

Spam email carrying malicious attachments or links, sent in bulk and serving as a primary vector for malware infections.

급여 가로채기 (Payroll Diversion)

A BEC scam that impersonates an employee to ask HR or payroll to change direct-deposit details, diverting wages to an attacker's account.

파밍 (Pharming)

An attack that redirects users to fraudulent websites via DNS poisoning or host-file manipulation even when they enter a legitimate address.

PhaaS (Phishing-as-a-Service)PhaaS

A cybercrime business model that sells phishing infrastructure, kits, and hosting as a subscription service, lowering the barrier to attacks.

피싱 킷 (Phishing Kit)

A pre-built package bundling fake login pages and collection scripts so non-experts can quickly deploy phishing sites.

프리텍스팅 (Pretexting)

A social-engineering technique where an attacker fabricates a plausible scenario or false identity to gain a victim's trust and extract information.

퀴드 프로 쿠오 (Quid Pro Quo)

A social-engineering technique that offers a service or benefit, such as fake tech support, in exchange for credentials or access.

리플라이 체인 공격 (Reply-Chain Attack)

An email attack that inserts malicious links or attachments into an existing reply chain from a compromised account so recipients open them without suspicion.

섹스토션 이메일 (Sextortion Email)

An extortion scam email that threatens to release supposed compromising sexual material unless the victim pays money such as Bitcoin.

스미싱 (Smishing)

A phishing attack delivered via SMS text messages using malicious links or fraudulent prompts to deceive users.

사회공학 (Social Engineering)

The manipulation of human psychology and trust, rather than technical vulnerabilities, to induce information disclosure or security bypass.

스팸 (Spam)

Unsolicited bulk email sent without recipient consent, often abused as a vector for phishing or malware distribution.

스팸 폭탄 (Spam Bombing)email bombing

An attack that floods a victim's inbox with massive email volume in a short time to bury legitimate security or fraud-alert notifications, often as a precursor to follow-on scams.

테일게이팅 (Tailgating)

A physical social-engineering technique of following an authorized person into a restricted area without credentials, also known as piggybacking.

스레드 하이재킹 (Thread Hijacking)

An attack that replies into an existing conversation thread from a compromised mailbox to insert malicious content while exploiting established trust.

타이포스쿼팅 (Typosquatting)

Registering misspelled variants of popular domains to capture users who make typing errors and redirect them to malicious sites.

URL 리디렉션 피싱 (Open Redirect Phishing)

A technique abusing open-redirect vulnerabilities on trusted sites so links appear legitimate but forward victims to malicious destinations.

보이스 피싱 (Vishing)

A social-engineering attack that uses phone or voice calls to deceive victims into divulging personal or financial information.

음성 복제 사기 (Voice Cloning Fraud)

A fraud technique where AI clones a target's voice from short samples to impersonate family or superiors and demand urgent money transfers.

워터링 홀 공격 (Watering Hole Attack)

A targeted attack that compromises websites frequently visited by a target group to infect their visitors.

무기화된 문서 (Weaponized Document)

An Office or PDF document manipulated with macros, exploits, or embedded objects to execute malware merely upon opening.

웨일링 (Whaling)

A form of spear phishing that targets high-profile executives such as CEOs or CFOs to exploit their authority and access to funds.

Email authentication

SPF

DNS record declaring which mail servers may send for a domain.

For executives (CEO·CISO)

Without it anyone can send as your domain and even your real mail gets flagged; it is a prerequisite for DMARC. Commonly missed: SPF has a 10-lookup limit that silently breaks as you add SaaS senders — review the record every time you add a sending tool.

Read more
DKIM

Cryptographic signature on a message that verifies it was not altered.

For executives (CEO·CISO)

Core to deliverability and tamper-proofing; unsigned mail is treated with suspicion by receivers. Commonly missed: short (1024-bit) keys and no rotation are common — standardize on 2048-bit keys with periodic rotation.

Read more
DMARC

Policy layer that enforces SPF/DKIM results (reject/quarantine) and reports.

For executives (CEO·CISO)

The most effective single step against domain spoofing, and increasingly a de-facto requirement for sending/partnering. Commonly missed: most stay at p=none (monitor) and block nothing — use the reports to fix legitimate senders, then move to quarantine→reject.

Read more
ARC

Chain that preserves and re-signs authentication results across relays/forwarders.

For executives (CEO·CISO)

Forwarding/lists break SPF/DKIM and bounce legitimate mail; ARC reduces those false positives and the friction they cause. Commonly missed: moving DMARC to reject without testing forwarding paths can mass-block real collaboration mail — test those flows first.

Read more
MX 레코드 (MX record)

DNS record pointing to a domain's inbound mail servers; inline gateways change it.

For executives (CEO·CISO)

Adopting inline (gateway) security routes mail through that system, which then becomes a single point of failure. Commonly missed: verify availability (redundancy) and fail-open/queue behavior at contract/design time — if the security system stalls, company mail can stall.

Read more
BIMI (Brand Indicators for Message Identification)BIMI

A standard that displays a brand's verified logo next to authenticated messages in the inbox for domains passing DMARC, with the logo validated via DNS and a Verified Mark Certificate.

DANE (DNS-based Authentication of Named Entities)DANE

A protocol that binds TLS certificates or public keys to DNS names using DNSSEC-protected TLSA records, enabling verification of server certificates for protocols such as SMTP without relying solely on CAs.

DKIM 셀렉터 (DKIM Selector)

An identifier used to distinguish among multiple DKIM keys for a domain; the corresponding public key is published at the DNS location selector._domainkey.domain.

DMARC 집계 리포트 (DMARC Aggregate Report / RUA)RUA

A periodic XML report sent by receiving servers to a domain owner, summarizing statistics on SPF, DKIM, and DMARC authentication results for the domain's mail.

DMARC 정렬 (DMARC Alignment)

The core DMARC requirement that the domain authenticated by SPF or DKIM match the domain in the message's From header, evaluated in strict or relaxed mode.

DNSSEC (Domain Name System Security Extensions)DNSSEC

Extensions that add digital signatures to DNS responses to provide data integrity and origin authentication, preventing DNS spoofing and cache poisoning and underpinning DANE.

순방향 비밀성 (Forward Secrecy)PFS

A TLS property using ephemeral per-session keys so that even if a long-term private key is later compromised, previously recorded encrypted traffic cannot be decrypted.

MTA-STS (SMTP MTA Strict Transport Security)MTA-STS

A mechanism letting a domain publish, over HTTPS, a policy requiring TLS encryption and certificate validation for inbound SMTP connections, defending against downgrade and man-in-the-middle attacks.

OpenPGP

An open standard for email encryption derived from PGP (RFC 4880 and successors) that defines message and key formats so implementations like GnuPG can interoperate.

PGP (Pretty Good Privacy)PGP

A public-key cryptography program for encrypting and signing email and files, using a web-of-trust model to validate keys.

리턴 패스 (Return-Path)

The envelope sender (MAIL FROM) address of an email, where bounce messages are returned, and whose domain is the basis for SPF verification and DMARC alignment.

S/MIME (Secure/Multipurpose Internet Mail Extensions)S/MIME

A standard for end-to-end signing and encryption of email messages using X.509 certificate-based public-key cryptography, providing message integrity, authentication, and confidentiality.

SMTP (Simple Mail Transfer Protocol)SMTP

The standard internet protocol for transmitting email between mail servers and from clients to servers; plaintext by default, it is secured with STARTTLS or SMTPS.

SMTPS (SMTP over TLS)SMTPS

A method of encrypting SMTP with TLS from the start of the connection (implicit TLS, typically port 465), encrypting from the outset rather than via the opportunistic upgrade of STARTTLS.

SPF 레코드 (SPF Record)

A DNS TXT record listing a domain's authorized sending mail servers, beginning with v=spf1 and composed of mechanisms like include, a, mx, ip4 and qualifiers such as -all.

STARTTLS

A command that opportunistically upgrades an existing plaintext protocol connection to a TLS-encrypted one, used in SMTP, IMAP, and POP3 to secure the transport while keeping standard ports.

TLS-RPT (SMTP TLS Reporting)TLS-RPT

A standard that lets domains using MTA-STS or DANE receive daily aggregate reports from sending mail servers about TLS negotiation successes and failures.

VMC (Verified Mark Certificate)VMC

A digital certificate issued by an authority that verifies a brand's trademark rights to a logo, used in BIMI to display a validated logo in the inbox.

Architecture & deployment

보안 이메일 게이트웨이SEG

Traditional inline filter that sits in front of MX, scanning mail before delivery.

For executives (CEO·CISO)

Blocking pre-delivery is powerful but invasive, and it is blind to already-delivered internal mail and account-takeover attacks. Commonly missed: a SEG breeds false comfort while BEC and internal spread sit in its blind spot — check whether API-based (ICES) visibility complements it.

Read more
통합 클라우드 이메일 보안ICES

Modern API-based approach that scans/remediates post-delivery on M365/Workspace — no MX change.

For executives (CEO·CISO)

Five-minute, no-MX, non-disruptive deployment means fast time-to-value, and it sees internal mail too — the market’s current direction. Commonly missed: being post-delivery, there is a brief window where a user may open it first — check claw-back speed and blocking policy for high-risk cases.

Read more
저널링 (Journaling)

Sending a copy of every message to the security system for non-disruptive monitoring/audit.

For executives (CEO·CISO)

Zero impact on mail flow makes it near-risk-free — ideal as a PoC / audit entry point. Commonly missed: journaling only observes, it does not block — plan the move to inline blocking after value is proven, rather than stopping at monitoring.

Read more
샌드박스 (Sandbox)

Isolated environment that detonates suspicious files/links to observe malicious behavior.

For executives (CEO·CISO)

Effective against unknown malicious attachments, but analysis takes time and advanced malware detects the sandbox and hides. Commonly missed: sandboxes focus on files/links and are useless against attachment-less BEC — do not treat one as complete email security.

Read more
콘텐츠 무해화·재구성CDR

Strips active content (e.g., macros) from attachments and rebuilds a safe version.

For executives (CEO·CISO)

It removes risk rather than judging it, so it holds up even against zero-day attachments. Commonly missed: stripping macros/embedded features can break business documents — pre-agree the impact and exceptions with macro-dependent teams (finance, engineering).

Read more
데이터 주권 (Data sovereignty)

Keeping data under the laws/control of its jurisdiction — achieved via on-prem / in-region deployment.

For executives (CEO·CISO)

Central to compliance (e.g., PIPA) and customer trust, and often decisive in public-sector/financial deals. Commonly missed: even a "cloud security" product may send message bodies to an external LLM or foreign region — verify where data is actually processed/stored (especially AI inference).

Read more
백스캐터 (Backscatter)

Collateral spam in which bounce messages or auto-replies to spam with forged sender addresses flood innocent third parties.

외부 발신 배너 경고 (External Sender Banner)

A security control that inserts a warning banner at the top of messages from outside the organization to raise user awareness.

사후 회수·교정 (Post-Delivery Remediation)

A core ICES capability that automatically retracts or removes messages already delivered to inboxes once they are found malicious, via API (clawback).

연결 제한 (Connection Throttling)

A mail server control that limits SMTP connection or send rates per source IP or domain to mitigate spam, abuse, and overload.

이메일 연속성 (Email Continuity)

An availability and disaster-recovery capability ensuring users can send and receive email even during a primary mail system outage.

이메일 데이터 유출 방지 (Email Data Loss Prevention)DLP

A technology that inspects outbound email content to detect, block, or encrypt unauthorized transmission of sensitive data.

이메일 암호화 게이트웨이 (Email Encryption Gateway)

A gateway solution that automatically encrypts outbound email according to policy to protect sensitive information.

이메일 격리 (Email Quarantine)

A feature that holds suspected spam, malware, or phishing email in a separate quarantine area instead of the inbox for admin or user review.

이메일 샌드박스 (Email Sandbox)

A technology that detonates suspicious attachments or URLs in an isolated virtual environment to dynamically analyze malicious behavior.

이메일 스풀링 (Email Spooling)

A capability that temporarily stores mail on a backup server when the destination is down and re-delivers it after recovery to prevent loss.

그레이리스팅 (Greylisting)

A technique that temporarily rejects email from unknown senders, relying on legitimate MTAs to retry, thereby filtering out spambots.

인터넷 메시지 접근 프로토콜 (Internet Message Access Protocol)IMAP

An email retrieval protocol that keeps messages on the server and allows synchronized access across multiple devices.

인라인 대 API 배포 (Inline vs API Deployment)

The two email security deployment models: inline, which sits in the mail flow to block in transit, versus API-based, which integrates with mailbox APIs to act post-delivery.

메일 큐 (Mail Queue)

A queue within an MTA that temporarily holds email that cannot be delivered immediately and manages retries.

메일 배달 에이전트 (Mail Delivery Agent)MDA

Software that delivers email received from an MTA into the recipient's mailbox.

메일 제출 에이전트 (Mail Submission Agent)MSA

A server that receives outgoing mail from clients, applies authentication and policy checks, and hands it to an MTA, typically over port 587.

메일 전송 에이전트 (Mail Transfer Agent)MTA

Software that transfers and routes email between mail servers using SMTP.

메일 사용자 에이전트 (Mail User Agent)MUA

Client software that lets users compose, read, and manage email, commonly known as an email client.

포스트 오피스 프로토콜 3 (Post Office Protocol 3)POP3

An email retrieval protocol that downloads messages from the server to a local client, typically removing them from the server.

실시간 블랙홀 목록 (Realtime Blackhole List)RBL

A reputation-based blocklist of IP addresses known to send spam, queried via DNS to reject mail.

평판 필터링 (Reputation Filtering)

A filtering technique that uses reputation scores based on the historical behavior of sending IPs or domains to block or allow mail.

스마트호스트 (Smarthost)

A designated external relay server through which a mail server routes all outbound email instead of delivering directly to destinations.

SMTP 릴레이 (SMTP Relay)

The process by which one mail server forwards email through another, which if misconfigured can be abused as an open relay.

SMTP 스머글링 (SMTP Smuggling)

An attack technique that exploits differing interpretations of message-end sequences between sending and receiving servers to inject spoofed email.

SMTP TLS (STARTTLS)TLS

Encrypting an SMTP connection via the STARTTLS command to protect message content in transit.

SMTPS 포트 465 (Implicit TLS SMTP)SMTPS

An SMTP submission port using implicit TLS where encryption applies from the start of the connection.

제출 포트 587 (Submission Port 587)

The standard SMTP submission port used by authenticated clients to submit mail, distinct from port 25 used for relaying.

클릭 시점 보호 (Time-of-Click Protection)

A protection that re-evaluates a link's safety at the moment a user clicks it, catching URLs weaponized after delivery.

전송 규칙 (Mail Flow/Transport Rule)

A mail flow policy rule that evaluates conditions on email and automatically applies actions such as blocking, redirecting, adding headers, or encryption.

URL 재작성 (URL Rewriting)

A technique that rewrites links in email to point to a security proxy so their safety is checked in real time at click time.

Operations & SOC

SIEM

Platform that aggregates and correlates security events/logs (Splunk, Sentinel, etc.).

For executives (CEO·CISO)

The hub for security visibility and compliance (audit logs); streaming email verdicts in pulls the whole attack picture together. Commonly missed: collecting logs nobody reviews just burns budget — define which alerts trigger which response (rules, owner, SLA) for the SIEM to actually pay off.

Read more
SOAR

Automated orchestration of incident response actions.

For executives (CEO·CISO)

It automates repetitive response in high-alert environments, with strong ROI in headcount and speed. Commonly missed: automating noisy alerts automates the mistakes too — start with high-confidence playbooks and keep a human-in-the-loop checkpoint.

Read more
침해 지표IOC

Forensic artifact that signals compromise (malicious IP, domain, file hash, …).

For executives (CEO·CISO)

The basic unit of threat sharing/blocking, but IOCs describe the known past and lag new attacks. Commonly missed: do not rely on IOC blocking alone — pair it with behavior/intent (TTP) detection to catch first-seen attacks.

Read more
격리 (Quarantine)

Remediation that moves/holds a risky message out of the inbox.

For executives (CEO·CISO)

A real defensive action, but false positives that quarantine legitimate mail breed friction and distrust of the security team. Commonly missed: without self-release, a review queue, and a release SLA, quarantine becomes "my mail vanished" complaints — design the operational process alongside it.

Read more
다중요소 인증MFA

Requires an extra authentication factor beyond a password, mitigating takeover.

For executives (CEO·CISO)

The highest-ROI single control — org-wide rollout should be a top priority. Commonly missed: SMS/push MFA falls to AiTM and MFA-fatigue attacks — upgrade high-risk accounts to phishing-resistant MFA (passkeys/FIDO2).

Read more
지능형 지속 위협 (Advanced Persistent Threat)APT

A targeted adversary that uses sophisticated techniques to maintain stealthy, long-term access. It is often associated with nation-state actors.

경보 피로 (Alert Fatigue)

The desensitization of analysts caused by an overwhelming volume of alerts, leading to missed critical threats. It is a major challenge in SOC operations.

감사 로그 (Audit Log)

A chronological record of activities and changes within a system. It is essential for accountability and post-incident investigation.

블루팀 (Blue Team)

A defensive team responsible for protecting assets and detecting and responding to attacks. They are the core staff of SOC operations.

침해 통지 (Breach Notification)

The mandatory process of informing regulators and affected individuals when a data breach occurs. It is required under regulations such as GDPR and data protection laws.

증거 연속성 (Chain of Custody)

The documented chronological handling of digital evidence to ensure its integrity. It is essential for legal admissibility.

명령제어 (Command and Control)C2

The communication channel and infrastructure attackers use to remotely control compromised systems. It is used for data exfiltration and issuing further commands.

침해사고대응팀 (Computer Emergency Response Team)CERT

A specialized organization that receives, coordinates, and responds to security incidents. They operate at national, sector, and organizational levels.

컴퓨터보안사고대응팀 (Computer Security Incident Response Team)CSIRT

A dedicated team responsible for handling security incidents within an organization. It performs detection, analysis, recovery, and post-incident activities.

사이버 킬 체인 (Cyber Kill Chain)

A model defined by Lockheed Martin describing the stages of a cyberattack. It breaks an attack into seven phases from reconnaissance to actions on objectives.

데이터 유출 (Data Exfiltration)

The unauthorized transfer of data from inside an organization to an external destination. It is often the ultimate goal of an attack.

디지털 포렌식·사고대응 (Digital Forensics and Incident Response)DFIR

A field combining forensic investigation with incident response. It simultaneously determines root cause and drives rapid remediation.

디지털 포렌식 (Digital Forensics)

The discipline of collecting, preserving, and analyzing digital evidence to determine the cause and course of an incident. It emphasizes legal admissibility.

엔드포인트 탐지·대응 (Endpoint Detection and Response)EDR

A solution that continuously monitors endpoint activity to detect, investigate, and respond to threats. It uses behavioral analysis to identify advanced attacks.

오탐 (False Positive)FP

An alert that incorrectly flags benign activity as a threat. Excessive false positives cause analyst fatigue and alert dismissal.

일반 개인정보보호법 (General Data Protection Regulation)GDPR

The European Union's regulation on personal data protection and processing. It includes breach notification obligations and strong penalties.

거버넌스·위험·컴플라이언스 (Governance, Risk and Compliance)GRC

An integrated approach to managing an organization's governance, risk management, and regulatory compliance. It aligns security decisions with business objectives.

사고대응 (Incident Response)IR

The structured process of detecting, containing, eradicating, and recovering from security incidents. Its goal is to minimize damage and restore normal operations.

공격지표 (Indicator of Attack)IOA

Indicators that reveal an attacker's intent and behavioral patterns. They focus on detecting an attack in progress before compromise completes.

ISO/IEC 27001ISO 27001

An international standard for information security management systems (ISMS). It requires risk-based controls and continual improvement.

횡적 이동 (Lateral Movement)

A technique where an attacker expands access from a compromised system to others within the network. It is used to reach target assets.

로그 관리 (Log Management)

The practice of collecting, storing, analyzing, and retaining system and application logs. It underpins detection, forensics, and compliance.

평균 탐지 시간 (Mean Time to Detect)MTTD

The average time taken to detect a security incident after it occurs. It is a key metric for SOC detection performance.

평균 대응 시간 (Mean Time to Respond)MTTR

The average time taken to respond to and remediate an incident after detection. It measures response efficiency.

MITRE ATT&CKATT&CK

A globally accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. It serves as a common framework for detection and defense.

네트워크 탐지·대응 (Network Detection and Response)NDR

A solution that analyzes network traffic to detect and respond to anomalous behavior and threats. It excels at identifying lateral movement and stealthy attacks.

NIST 사이버보안 프레임워크 (NIST Cybersecurity Framework)NIST CSF

A cybersecurity management framework from the U.S. NIST organized around Identify, Protect, Detect, Respond, and Recover functions. It provides a common language for risk management.

PCI DSSPCI DSS

A security standard that organizations handling payment card data must comply with. It governs the storage, transmission, and processing of cardholder data.

지속성 (Persistence)

Techniques that allow an attacker to maintain access across reboots or credential changes. It is one of the key tactics in MITRE ATT&CK.

플레이북 (Playbook)

A standardized set of procedures for responding to a specific type of incident. It forms the basis for SOAR automation.

권한 상승 (Privilege Escalation)

An attack technique for gaining higher privileges from a lower-privileged context. It is a key step toward system control and persistence.

퍼플팀 (Purple Team)

An exercise that has offensive (red team) and defensive (blue team) collaborate to improve detection and response. It integrates feedback from both sides.

레드팀 (Red Team)

An offensive team that emulates real adversaries to test an organization's defenses. It exposes gaps in detection and response.

런북 (Runbook)

A step-by-step guide documenting operational tasks or response procedures. It ensures consistency and repeatability.

보안관제센터 (Security Operations Center)SOC

A centralized team and facility that continuously monitors, detects, and responds to security events. It combines analysts, processes, and technology to manage threats.

시그마 룰 (Sigma Rule)

A generic, vendor-agnostic format for log-based detection rules. It allows a rule to be written once and converted for multiple SIEM platforms.

SOC 2SOC 2

An AICPA audit report attesting to a service organization's adherence to trust principles such as security, availability, and confidentiality. It is widely used by SaaS firms to demonstrate trustworthiness.

STIXSTIX

A standardized language for representing structured cyber threat intelligence. It supports consistent sharing of threat information.

시스로그 (Syslog)

A standard protocol used by network devices and systems to send log messages. It is widely used for centralized log collection.

테이블탑 훈련 (Tabletop Exercise)

A discussion-based exercise that walks through a hypothetical incident scenario. It surfaces gaps in procedures and communication beforehand.

전술·기법·절차 (Tactics, Techniques and Procedures)TTP

A concept describing adversary behavior at the levels of tactics, techniques, and procedures. It serves as the basis for threat analysis and detection.

TAXIITAXII

A transport protocol for exchanging STIX-based threat intelligence. It enables automated sharing of threat information.

위협 행위자 (Threat Actor)

An individual or group responsible for causing a security incident. They are classified by motivation, capability, and resources.

탐지 룰 (Detection Rule)

A rule defining specific malicious patterns or conditions that trigger alerts. It is the basic unit of SIEM and EDR detection logic.

위협 헌팅 (Threat Hunting)

The proactive, hypothesis-driven search for threats that evade existing detection tools. Analysts actively look for signs of compromise.

위협 인텔리전스 (Threat Intelligence)CTI

Collected and analyzed information about threat actors and attacks. It supports defensive decision-making and proactive response.

사용자·엔티티 행위 분석 (User and Entity Behavior Analytics)UEBA

Technology that learns baselines of normal user and entity behavior to detect anomalies. It is effective at spotting insider threats and account takeover.

확장 탐지·대응 (Extended Detection and Response)XDR

A solution that unifies detection and response across endpoints, network, cloud, and email layers. It provides visibility beyond isolated security silos.

YARA

A tool and rule language for identifying and classifying malware based on patterns. It is widely used in malware hunting and forensics.

AI & detection engine

LLM / sLLM

Large language models and self-hostable small models (sLLM), used for intent classification.

For executives (CEO·CISO)

Powerful at catching subtle intent (impersonation, payment pressure), but a hosted LLM effectively sends message bodies outside. Commonly missed: "has AI" matters less than where data goes — if sovereignty matters, confirm an sLLM/on-prem option and cost control (tiering).

Read more
인공신경망 (ANN)

Standard neural network (dense, continuous) — transformers/LLMs belong here (our shipped engine).

For executives (CEO·CISO)

Today's mainstream with high accuracy, but GPU/inference cost and power are the key operational variables. Commonly missed: running every email through the model explodes cost — verify there is cost-tiering (rules first, model only for ambiguous cases).

Read more
스파이킹 신경망 (SNN)

Third-generation, event-driven spiking network — ultra-low-power and streaming-friendly (research).

For executives (CEO·CISO)

Strong future potential for low-power/edge inference, but still research — not a buying factor today. Commonly missed: if a vendor markets "SNN/neuromorphic," verify whether it is shipping or merely roadmap/research (watch for overclaiming).

Read more
검색증강생성 (RAG)

Retrieves external knowledge (threat intel) to ground the model’s judgment.

For executives (CEO·CISO)

Adds fresh threat knowledge and grounding to model decisions, improving explainability and trust. Commonly missed: if the retrieved knowledge is stale, so is the RAG — check the intel update cadence and source quality.

Read more
에이전트형 AI (Agentic AI)

Analyst-like automation where specialist agents combine clues to judge intent.

For executives (CEO·CISO)

Augments scarce security staff and, like a human analyst, combines clues to catch targeted attacks. Commonly missed: trust hinges on explainability of "why it decided that" — check whether the product traces its reasoning or just emits a black-box score.

Read more
적대적 예제 (Adversarial Example)

An input subtly perturbed to be misclassified by a model while appearing normal to humans. A core threat in ML security.

적대적 머신러닝 (Adversarial Machine Learning)AML

The study of attacks that deceive or subvert machine learning models, and the defenses against them.

AI 에이전트 (AI Agent)

An autonomous LLM-based system that invokes tools and reasons over multiple steps to accomplish goals.

AI 정렬 (AI Alignment)

The research field of steering AI systems' goals and behavior toward human intent and values. Central to safe LLM operation.

이상 탐지 (Anomaly Detection)

A technique for identifying data or behavior that deviates from normal patterns. Central to intrusion and fraud detection.

어텐션 메커니즘 (Attention Mechanism)

A neural network technique that weights the most relevant parts of an input sequence. A key component of the Transformer.

백도어 공격 (Backdoor Attack)

An attack that implants a hidden function in a model so it behaves maliciously only when a specific trigger is present.

분류기 (Classifier)

A model that assigns inputs to one of a set of predefined categories. Used for spam/ham and malicious/benign decisions.

혼동 행렬 (Confusion Matrix)

An evaluation table that cross-tabulates a classifier's predictions versus true labels, showing TP, FP, TN, and FN.

데이터 포이즈닝 (Data Poisoning)

An attack that injects malicious samples into training data to manipulate a model's performance or behavior.

딥러닝 (Deep Learning)DL

A subfield of machine learning using multi-layer neural networks to learn complex representations. Applied to image- and text-based threat detection.

임베딩 (Embedding)

A dense vector representation that captures the semantic meaning of words or documents. Forms the basis of similarity search and RAG.

설명 가능한 AI (Explainable AI)XAI

Techniques and a field for making AI model predictions interpretable to humans. Important for trusting detection outcomes.

F1 점수 (F1 Score)

The harmonic mean of precision and recall, summarizing classification performance in a single value.

거짓양성률 (False Positive Rate)FPR

The rate at which actual negatives are incorrectly classified as positive. Directly linked to alert fatigue in detection systems.

특징 공학 (Feature Engineering)

The process of transforming and selecting raw data into features suitable for a model. Greatly impacts detection performance.

파인튜닝 (Fine-tuning)

The process of further training a pre-trained model on task- or domain-specific data. Used to specialize security classifiers.

생성적 적대 신경망 (Generative Adversarial Network)GAN

A neural architecture where a generator and discriminator compete during training. Used to create deepfakes and synthetic attack data.

그래디언트 부스팅 (Gradient Boosting)

An ensemble technique that sequentially combines weak learners to reduce error. Used in detection models such as XGBoost.

가드레일 (Guardrails)

Safety controls that inspect and constrain LLM inputs/outputs to block harmful or policy-violating content.

환각 (Hallucination)

The phenomenon where an LLM plausibly generates false or unsupported content. Treated as a reliability threat.

탈옥 (Jailbreak)

A technique that bypasses safety guardrails to make an LLM produce prohibited content. Carried out through prompt manipulation.

머신러닝 (Machine Learning)ML

A branch of AI where systems learn patterns from data to make predictions or classifications without explicit programming. Widely used in security for spam and malware detection.

멤버십 추론 공격 (Membership Inference Attack)MIA

A privacy attack that infers whether a specific data point was part of a model's training set.

모델 컨텍스트 프로토콜 (Model Context Protocol)MCP

An open protocol that standardizes how LLM applications connect to external tools and data sources.

회피 공격 (Evasion Attack)

An attack that manipulates inputs at inference time to evade a detection model. Common in malware detection bypass.

모델 추출 공격 (Model Extraction Attack)

An attack that replicates a target model's functionality or parameters through repeated query-response probing.

모델 역전 공격 (Model Inversion Attack)

A privacy attack that reconstructs sensitive training inputs by analyzing a model's outputs.

나이브 베이즈 (Naive Bayes)

A probabilistic classifier based on Bayes' theorem assuming feature independence. A standard for early spam filtering.

자연어 처리 (Natural Language Processing)NLP

The AI field enabling computers to understand and generate human language. Applied to phishing text analysis.

인공신경망 (Neural Network)NN

A computational model of interconnected nodes inspired by biological neurons. Forms the basis of pattern recognition and anomaly detection.

과적합 (Overfitting)

When a model fits the training data too closely and fails to generalize to new data.

OWASP LLM Top 10

An OWASP list cataloging the ten most critical security risks for large language model applications.

정밀도와 재현율 (Precision and Recall)

Precision is the fraction of positive predictions that are correct; recall is the fraction of actual positives detected. Key evaluation metrics.

랜덤 포레스트 (Random Forest)

A machine learning algorithm that ensembles many decision trees for prediction. Frequently used for malicious traffic classification.

AI 레드팀 (AI Red Teaming)

An adversarial evaluation that deliberately probes an AI model for vulnerabilities and harmful outputs.

강화 학습 (Reinforcement Learning)RL

Learning an action policy by optimizing for reward signals. Researched for automated defense and penetration simulation.

인간 피드백 강화학습 (RLHF)RLHF

A reinforcement learning method that aligns models using human preference feedback as reward. Used to suppress harmful LLM outputs.

ROC AUCAUC

The area under the true-positive-rate vs false-positive-rate curve across thresholds, measuring classifier performance.

지도 학습 (Supervised Learning)

Learning an input-output mapping from labeled data. Used for label-based detection such as spam/ham classification.

서포트 벡터 머신 (Support Vector Machine)SVM

A classification algorithm that finds a hyperplane maximizing the margin between classes. Used in classic spam filters.

토큰화 (Tokenization)

The preprocessing step of splitting text into smaller units called tokens for model input.

전이 학습 (Transfer Learning)

A machine learning approach that reuses knowledge learned on one task for a related task. Useful in data-scarce security domains.

트랜스포머 (Transformer)

A neural network architecture based on the self-attention mechanism, the core of modern LLMs. Excels at processing sequential data.

비지도 학습 (Unsupervised Learning)

Learning structure or patterns from unlabeled data. Used in clustering-based anomaly detection.

벡터 데이터베이스 (Vector Database)

A database that stores embedding vectors and performs approximate nearest-neighbor search. Used in RAG and semantic search.

General security & latest trends

랜섬웨어 / RaaS

Malware that encrypts data for ransom; RaaS sells it as a subscription criminal service.

For executives (CEO·CISO)

It mostly starts with phishing/credential theft, so email security is the first line of prevention; RaaS lowers the barrier so targets are not just large firms. Commonly missed: backups that get encrypted/deleted too are useless — ensure offline/immutable backups, real recovery drills, and a plan for data-leak extortion (double extortion).

Read more
중간자 피싱 (AiTM)AiTM

Real-time proxy phishing that steals session tokens to bypass even MFA (rapidly rising).

For executives (CEO·CISO)

It breaks the "MFA means safe" assumption and is rising fast — stealing the token opens the account even with password and MFA intact. Commonly missed: ordinary MFA will not stop it — add phishing-resistant MFA (passkeys/FIDO2) and anomalous-session/device detection.

Read more
MFA 피로 공격 (MFA fatigue)

Flooding a user with MFA push prompts until they approve one by accident.

For executives (CEO·CISO)

It targets human fatigue, not technology — enabling MFA is not the end. Commonly missed: switch to number-matching / phishing-resistant MFA and train staff to "deny and report any unexpected MFA prompt."

Read more
딥페이크 (Deepfake)

AI-synthesized voice/video used to impersonate execs, supercharging BEC and vishing.

For executives (CEO·CISO)

In an era where even a phone voice or video call can be faked — with real large-wire-fraud cases reported — voice and face, the last trust anchors, fall. Commonly missed: "just call to confirm" is no longer safe for big transactions — build verification that separates channels/factors (pre-agreed code words, callback numbers, multi-party approval).

Read more
프롬프트 인젝션 (Prompt injection)

Injecting hidden instructions into an AI model to make it act against intent (an LLM-era threat).

For executives (CEO·CISO)

Adopting AI in workflows/products creates an entirely new attack surface (e.g., hidden instructions in mail/docs hijacking an AI assistant). Commonly missed: it is absent from legacy checklists — add AI input trust-boundaries, output guardrails, and least-privilege for the AI’s permissions to your security review.

Read more
섀도 AI (Shadow AI)

Data-leak risk from staff feeding sensitive info into unsanctioned AI tools.

For executives (CEO·CISO)

Driven by productivity, staff are likely already pasting code, customer data, and contracts into unsanctioned AI. Commonly missed: an outright ban just drives it underground — combine a safe sanctioned alternative, a clear AI-use policy, and DLP to stop sensitive-data leakage.

Read more
제로 트러스트 (Zero Trust)

"Never trust, always verify" — access governed by identity/context, not network location.

For executives (CEO·CISO)

As "inside the network = safe" collapses in the remote/cloud era, it has become the de-facto baseline. Commonly missed: Zero Trust is a journey, not a product — do not try to buy it at once; roll out incrementally starting with MFA, least privilege, segmentation, and device trust.

Read more
공급망 공격 (Supply chain attack)

Compromising a trusted vendor, software, or update channel to hit many at once.

For executives (CEO·CISO)

Even with perfect internal security, a compromised trusted third party (vendor, open source, update) breaches you anyway. Commonly missed: scoping security to your own perimeter — formalize vendor due-diligence, software bills of materials (SBOM), and least-privilege integrations.

Read more
EDR / XDR

Detection & response on endpoints (EDR), extended across email/cloud/network (XDR).

For executives (CEO·CISO)

Visibility linking email, endpoint, and cloud lets you trace the full path (mail click → device infection → spread). Commonly missed: installing the tool without 24/7 monitoring/response staff just piles up alerts — confirm in-house capacity or an MDR (managed response) plan.

Read more
데이터 유출 방지DLP

Controls that detect and block sensitive data from leaving (email, uploads, etc.).

For executives (CEO·CISO)

Core to compliance and trade-secret protection, with outbound email the most common leak path. Commonly missed: too-strict rules block work, too-loose rules leak — design classification, exceptions, and training together, and include accidental leaks (misdirected mail).

Read more
내부자 위협 (Insider threat)

Harm from insiders (malicious or careless); a hijacked account also behaves like one.

For executives (CEO·CISO)

Focusing on external defense, orgs overlook insiders who hold the most access — and a hijacked account ultimately behaves like a normal insider. Commonly missed: beyond least privilege and behavior monitoring, enforce immediate access revocation on departure/role-change (offboarding) — a frequent failure point.

Read more
피싱 저항 MFA (Passkey / FIDO2)

Authentication resistant to phishing/AiTM (passkeys, FIDO2 keys); the passwordless direction.

For executives (CEO·CISO)

The strongest available answer to AiTM/credential theft — token interception simply stops working. Commonly missed: org-wide rollout takes time, so start with high-risk accounts (execs, admins, finance) and set up loss/recovery procedures alongside.

Read more
초기 침투 브로커IAB

Criminals who breach orgs and sell the access to others (e.g., ransomware crews).

For executives (CEO·CISO)

A sign cybercrime has specialized — one group breaches and sells the "key," another monetizes it with ransomware, so a small breach becomes a big incident. Commonly missed: treating "minor" phishing/credential leaks as harmless — blocking initial access and fast credential revocation IS ransomware prevention.

Read more
공격 표면 관리ASM

Continuously discovering/managing exposed assets, domains, and services to shrink attack paths.

For executives (CEO·CISO)

You cannot protect assets you do not know about, and forgotten servers, test domains, and stale SaaS accounts are the most common entry points. Commonly missed: a one-time asset inventory goes stale fast — include continuous automated discovery plus monitoring of lookalike domains and exposed services.

Read more
지능형 지속 위협 (APT)APT

A sophisticated, prolonged, and stealthy intrusion by a well-resourced adversary to achieve specific goals. Often conducted by nation-state groups.

봇넷 (Botnet)

A network of compromised devices remotely controlled by an attacker. It is used for DDoS, spam, and cryptomining.

무차별 대입 공격 (Brute-Force Attack)

An attack that systematically tries all possible passwords or key combinations to break authentication. Weak passwords are especially vulnerable.

클라우드 액세스 보안 브로커 (CASB)CASB

A security broker that sits between users and cloud services to enforce policy and provide visibility. It helps control shadow IT.

크리덴셜 스터핑 (Credential Stuffing)

An attack that automatically tries leaked username-password pairs against other services to hijack accounts. It exploits password reuse.

클라우드 보안 형상 관리 (CSPM)CSPM

A tool that continuously assesses and remediates misconfigurations and compliance gaps in cloud environments. It reduces risk from improper configuration.

크로스 사이트 요청 위조 (CSRF)CSRF

An attack that tricks an authenticated user into executing unintended requests. It performs actions using the victim's privileges.

분산 서비스 거부 공격 (DDoS)DDoS

An attack that floods a target service with traffic from many devices to disrupt it. It undermines availability.

종단 간 암호화 (End-to-End Encryption)E2EE

An encryption method where only the sender and recipient can decrypt the message. Even intermediary servers cannot read the content.

방화벽 (Firewall)

A security device or software that allows or blocks network traffic based on defined rules. It protects internal networks from external threats.

신원 및 접근 관리 (IAM)IAM

A framework for identifying users and managing their access to resources. It encompasses authentication and authorization.

침입 탐지·방지 시스템 (IDS/IPS)IDS/IPS

Security systems that detect (IDS) or actively block (IPS) malicious activity on networks or hosts. They operate on signatures or anomaly detection.

키로거 (Keylogger)

A tool that secretly records a user's keystrokes. It is used to steal passwords and sensitive information.

리빙 오프 더 랜드 (Living off the Land)LOTL

A technique that abuses legitimate tools already present on a system, such as PowerShell, to evade detection. It operates without dropping extra malware.

악성코드 (Malware)

A general term for malicious software designed to harm or gain unauthorized access to systems. It includes viruses, worms, and trojans.

중간자 공격 (Man-in-the-Middle)MITM

An attack where the adversary intercepts or alters communication between two parties. Unencrypted communications are especially vulnerable.

OAuthOAuth

An authorization protocol that lets users delegate limited access to third-party apps without sharing passwords. It operates using tokens.

특권 접근 관리 (PAM)PAM

A security discipline that controls, monitors, and audits access by high-privilege accounts. It mitigates misuse and credential theft.

양자내성 암호 (Post-Quantum Cryptography)PQC

Cryptographic algorithms designed to resist attacks by quantum computers. Standardization is underway to replace classical public-key schemes.

공개키 암호 (Public-Key Cryptography)

An asymmetric cryptography scheme using a public-private key pair for encryption and digital signatures. It enables secure communication without prior key exchange.

루트킷 (Rootkit)

A stealthy malicious toolset that hides deep in a system to maintain privileged access and evade detection. It conceals activity at the OS level.

보안 액세스 서비스 엣지 (SASE)SASE

An architecture that delivers networking and security functions as a unified cloud service. It combines SD-WAN with zero-trust security.

스파이웨어 (Spyware)

Malware that covertly monitors activity and exfiltrates collected information. It steals keystrokes, screens, and credentials.

SQL 인젝션 (SQL Injection)SQLi

An attack that injects malicious SQL statements into input to manipulate a database. It can lead to data exfiltration or tampering.

통합 인증 (SSO)SSO

An authentication scheme that lets users access multiple applications with a single login. It improves usability and credential management.

전송 계층 보안 (TLS)TLS

A standard protocol that encrypts network communication and provides integrity and authentication. It underpins HTTPS and succeeds SSL.

트로이목마 (Trojan Horse)

Malware disguised as legitimate software to trick users into running it. It is used to install backdoors or steal data.

가상 사설망 (VPN)VPN

A technology that creates an encrypted tunnel over public networks for secure communication. It is used for remote access and privacy.

웜 (Worm)

Malware that self-replicates and spreads across networks without user interaction. Its rapid propagation can cause widespread damage.

크로스 사이트 스크립팅 (XSS)XSS

An attack that injects malicious scripts into web pages to run in other users' browsers. It is used for session hijacking and more.