추상적인 헤더 이미지

위협 인텔리전스란 무엇인가요?

Subscribe to our newsletter

Cyber Daily™를 통해 최신 위협 인사이트를 이메일로 받아보세요

무료 구독

Top view of office desk with laptop, coffee cup, cactus and pencils on the black and gray background. Flat lay.
/blog/july-2026-cve-landscape
/blog/june-2026-cve-landscape

위협 인텔리전스란 무엇인가요?

위협 인텔리전스는 사이버 공격에 대한 증거 기반 정보를 분석하여 사이버 보안 전문가가 상황에 맞는 문제를 파악하고 탐지된 문제에 대한 맞춤형 솔루션을 만들 수 있도록 지원합니다.

Rooted in data, similar to open source intelligence (OSINT), threat intelligence provides context — like who is attacking you, what their motivation and capabilities are, and what indicators of compromise (IOCs) in your systems to look for — that helps you make informed decisions about your security.

As digital transformation reshapes industries, the importance of cybersecurity grows exponentially. A Statista study predicts that by 2033, the Cyber Threat Intelligence (CTI) market will surge beyond $44 billion U.S. dollars, underscoring the critical role of informed, data-driven defenses in modern business strategies. This corresponds with the results from our recent survey in the Recorded Future 2025 State of Threat Intelligence report, which showed that 91% of participants plan to increase their threat intelligence investment in 2026.

이 문서에서는 위협 인텔리전스가 사이버 위험을 효과적으로 탐지, 분석 및 완화하여 사전 예방적 보안 접근 방식을 보장하는 방법에 대해 심층적으로 설명합니다. 구성 요소, 중요성, 침입 및 공격을 방지하기 위해 조직 내에서 구현하는 방법에 대해 알아보세요.

Key Takeaways

Hardware in the server room and Diagnostics - 3D Rendering

For a more detailed overview of all things Threat Intelligence

Download the comprehensive Intelligence Handbook or keep reading below.

다운로드

Defining Threat Intelligence and Its Importance

Threat intelligence involves gathering, processing, and analyzing data to discern the motives, behaviors, and targets of threat actors, providing actionable insights to prevent and combat cybercrime.

위협 인텔리전스란 무엇인가요?

사이버 보안은 조직에 새로운 사이버 위협을 비롯한 잠재적 사이버 위협에 대한 증거 기반 인사이트를 제공하여 선제적으로 방어를 강화하고 정보에 입각한 보안 결정을 내리는 데 필요한 지식을 제공하는 진화하는 학문입니다.

Gartner에 따르면 위협 인텔리전스는 기존 또는 새로운 위협에 대한 맥락과 실행 가능한 조언을 포함한 증거 기반 인사이트를 제공하여 대응 전략에 정보를 제공합니다.

위협 인텔리전스는

Interpreting threat intelligence enables organizations to comprehend the risks they face and enact proactive measures to mitigate potential damage.
This includes raw data from internal systems, security controls, and cloud services, all of which lay the groundwork for a solid cyber threat intelligence program.

목표는 위협이 유효하다는 증거와 효율적인 완화 방법을 제안하는 실행 가능한 인사이트를 모두 제공하는 것입니다.

Why threat intelligence matters

Threat intel plays a pivotal role in cybersecurity by helping organizations understand potential cyber threats, including threats that could specifically target and impact their business. Investing in a robust cyber threat intelligence program allows organizations to reduce the risk of cyberattacks and strengthen their security posture.

In the world of cybersecurity, challenges abound. There's the sheer volume of data to contend with, the rapid evolution of attack vectors, and the scarcity of skilled cybersecurity personnel. However, threat intelligence provides a solution. Integrating, prioritizing, and authenticating data from various sources helps threat intelligence alleviate data overload.

Types of Threat Intelligence + Use Cases

Cyber threat intelligence comes in various forms, each serving distinct purposes and catering to different decision-making levels within an organization. These forms include strategic, operational and tactical threat intelligence.

전략적 위협 인텔리전스

Strategic threat intelligence offers a comprehensive understanding of the threat landscape. This holistic approach helps organizations make informed decisions to protect against potential threats. It offers:

This intelligence gives organizations a comprehensive view of the threat landscape and helps them stay ahead of potential threats. It's designed for non-technical stakeholders, such as company boards, who rely on its high-level decision-making guidance.

Security leaders must balance limited resources with the need to protect against evolving threats. Threat intelligence helps map the threat landscape, assess risk, and provides the necessary context for making informed, timely decisions.

As organizations digitize and expand data collection, traditional risk management methods fall short, lacking the necessary context for modern security challenges. Threat intelligence provides real-time insights into third-party threat environments, enhancing risk assessment and management.

운영 위협 인텔리전스

Operational threat intelligence focuses on understanding specific threats and campaigns. It provides real-time insights and actionable recommendations for dealing with and understanding security vulnerabilities and attack techniques. Studying past attacks and drawing conclusions about threat actors' tactics, techniques, and procedures (TTPs) helps organizations understand the “who,” “why,” and “how” of each cyber attack.

In incident response and triage, threat intelligence plays a pivotal role. It allows for the measurement of key performance metrics such as Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR), aiding in the evaluation of incident response effectiveness.

위협 인텔리전스를 사고 대응에 통합하면 조직은 대응 시간을 크게 단축하여 비즈니스 연속성과 데이터 보호를 유지할 수 있습니다.

Within security operations, threat intelligence plays a critical role in proactively identifying and mitigating sophisticated cyber threats, such as advanced persistent threats. AI technologies and behavioral analytics enhance the ability to find threats by developing profiles for network applications and analyzing user and device data.

To keep your organization safe, it's crucial to prevent fraudulent uses of your data or brand. Integrating threat intelligence from both underground and surface sources offers deep insights into the tactics and motivations of threat actors.

전술적 위협 인텔리전스

Tactical threat intelligence centers on outlining the tactics, techniques, and procedures (TTPs) employed by threat actors. It provides vital insights into their methods and strategies. By offering actionable threat intelligence, tactical intelligence provides insights into the immediate threat landscape, enabling teams to adapt to changing attacker behaviors and threats.

Cyber threat intelligence services contribute significantly to the effectiveness of tactical intelligence. Modeling potential attacks using industry-wide threat information helps organizations better prepare for specific threats.

In vulnerability management, an effective threat intelligence program is vital. It identifies critical vulnerabilities being actively exploited, enabling organizations to prioritize patching and preemptively address potential software vulnerabilities.

The Threat Intelligence Lifecycle

Understanding the various forms of threat intelligence is one thing, but navigating the threat intelligence lifecycle is another. This lifecycle is made up of six stages:

Each stage plays a crucial role in ensuring continuous improvement and refinement of the intelligence process. But what does each stage involve, and why is each one critical?

1. Requirements and Direction

The direction phase is where it all begins. Here, the goals for the cyber threat intelligence program are established, with key stakeholder input. Intelligence requirements are set to answer cybersecurity questions relevant to the organization. Stakeholder feedback is crucial for understanding the intelligence priorities of the security teams utilizing the cyber threat intelligence, which in turn guides the documentation of these intelligence requirements.

2. 컬렉션

방향이 설정되면 데이터 수집에 초점을 맞춥니다. 여기에는 보안 로그, 위협 피드, 전문가 인터뷰 등 다양한 내부 및 외부 소스에서 정보를 수집하는 작업이 포함됩니다. 목표는 위협 인텔리전스 라이프사이클의 다음 단계에 정보를 제공하기 위해 가능한 한 많은 관련 데이터를 수집하는 것입니다.

3. Processing and Organization

데이터 수집 후에는 처리가 이루어집니다. 이 단계에서는 수집된 데이터를 사용 가능한 형식으로 변환합니다. 여기에는 관련 없는 데이터를 걸러내고 나머지 정보를 구조화하여 효율적으로 분석하는 작업이 포함됩니다. 인공 지능과 머신 러닝의 도움으로 트렌드를 파악하여 다음 단계에 필요한 귀중한 인사이트를 얻을 수 있습니다.

4. 분석

위협 인텔리전스 분석 단계에는 다음이 포함됩니다:

5. 보급

Once the analysis is complete, the dissemination phase ensures that the key recommendations and conclusions are received by the relevant stakeholders. The format of dissemination can vary, ranging from formal threat intelligence reports to video feeds or presentations, depending on the audience's needs.

6. 피드백

마지막으로, 피드백은 사이버 위협 인텔리전스 수명 주기의 중요한 구성 요소입니다. 이를 통해 제공되는 인텔리전스가 조직의 변화하는 요구와 우선순위를 충족하도록 보장합니다. 피드백 단계에서 확인된 새로운 질문이나 인텔리전스 격차는 다음 주기에서 해결하여 지속적인 개선과 개선을 보장할 수 있습니다.

How Does Machine Learning Contribute to Better Threat Intelligence?

오늘날의 대규모 데이터 처리에는 오픈 웹, 딥 웹, 다크 웹, 기술 채널 등 다양한 소스의 데이터를 효과적으로 결합하여 종합적인 개요를 생성할 수 있는 자동화가 필요합니다.

Recorded Future는 데이터를 카테고리로 구조화하고, 여러 언어의 텍스트를 분석하고, 위험 점수를 제공하고, 예측 모델을 생성하는 등 네 가지 방식으로 머신러닝 기술을 사용하여 위협 데이터 수집 및 집계를 개선합니다.

더 나은 위협 인텔리전스를 위한 머신 러닝

Threat Intelligence Tools and Services

위협 인텔리전스 플랫폼, 위협 데이터 피드, 인공 지능은 모두 사이버 위협 인텔리전스 기능을 향상하고 프로세스를 간소화하는 데 중요한 역할을 합니다. 그렇다면 이러한 위협 인텔리전스 도구와 서비스는 무엇이며 위협 인텔리전스 프로세스에 어떻게 기여할까요?

위협 인텔리전스 플랫폼

위협 인텔리전스 플랫폼 (TIP)은 외부 위협 피드를 내부 데이터와 통합하여 신속한 평가, 우선 순위가 지정된 위험 평가, 스마트 위협 데이터 분석 및 시각화 등의 기능을 제공합니다. 사이버 위협 인텔리전스 플랫폼은 더 넓은 시장과 조직의 산업과 관련된 위협에 대한 세분화된 가시성을 제공하며, 이는 팀의 효과적인 대응과 새로운 과제에 대한 적응에 매우 중요합니다.

위협 데이터 피드

Threat data feeds deliver current information such as threat actor TTPs, vulnerabilities, and new attacks. They comprise a diverse set of information, such as:

이러한 피드를 통해 의사 결정 프로세스를 간소화하고 대응책을 더 빠르게 배포할 수 있습니다.

Threat Intelligence FAQs

위협 인텔리전스의 3P는 무엇인가요?

위협 인텔리전스의 3P는 선제적, 예측적, 예방적입니다. 이러한 접근 방식은 잠재적 위협이 현실화되기 전에 적극적으로 찾아내어 식별함으로써 보안 전문가의 위협 인텔리전스 역량을 강화하는 데 핵심적인 역할을 합니다.

위협 인텔리전스 팀은 어떤 일을 하나요?

Threat data is raw information, such as IP addresses, domains, file hashes, malware signatures, or security trend data. Threat intelligence takes that data further by adding context, analysis, and actionable guidance so security teams can understand what the information means and how to respond.

What is the difference between threat data and threat intelligence?

Threat data is raw information, such as IP addresses, domains, file hashes, malware signatures, or security trend data. Threat intelligence takes that data further by adding context, analysis, and actionable guidance so security teams can understand what the information means and how to respond.

What are examples of threat intelligence?

Examples of threat intelligence include information about threat actor tactics, techniques, and procedures; indicators of compromise; vulnerabilities being actively exploited; malicious infrastructure; fraud activity; and broader trends affecting an organization’s industry or third-party ecosystem.

위협 인텔리전스 플랫폼이란 무엇인가요?

A threat intelligence platform, or TIP, integrates external threat feeds with internal data to help security teams assess, prioritize, analyze, and visualize threat information. These platforms help organizations understand which threats are most relevant to their business and respond more efficiently.

Where Does Your Security Strategy Stand?

Before you can effectively scale your defenses, you need to understand your current baseline. Take our quick, interactive Threat Intelligence Maturity Assessment to evaluate your organization’s capabilities, uncover potential blind spots, and receive tailored insights on how to elevate your security posture.

사이버 보안 전략을 강화하기 위한 전문가 인사이트, 보고서 및 도구를 살펴보세요.