본문 바로가기
  • Home

A Study on the Empirical Analysis of South Korea's Cyber Threat Landscape and Internet-Exposed Asset Vulnerabilities through the Integration of Shodan EASM and Threat Intelligence

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2026, 31(7), pp.127~140
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : May 13, 2026
  • Accepted : June 17, 2026
  • Published : July 31, 2026

Seung Han Yoon 1 Ah Reum Kang 1

1배재대학교

Accredited

ABSTRACT

This paper presents a comprehensive analysis of South Korea's cyber threat landscape and internet-exposed asset vulnerabilities by integrating Shodan EASM scan data (April 11, 2026) with CYFIRMA threat intelligence. The scan identified over 37.17 million exposed ports, with 538,230 hosts vulnerable under CISA KEV and 1,820,536 under VulnCheck KEV. Critical findings include 4,321 ICS/OT devices directly exposed to the internet, 25,742 unauthenticated databases, 1,171 BlueKeep-unpatched systems, and 50 hosts with confirmed remote code execution vectors. North Korea-linked APT groups including Lazarus Group, Kimsuky, and APT37, alongside ransomware operators Qilin and LockBit, are actively exploiting these vulnerabilities. This paper proposes a tiered security roadmap with immediate (0-30 days), short-term (1-6 months), and long-term (6+ months) countermeasures, along with sector-specific priority action matrices.

Citation status

* References for papers published after 2025 are currently being built.