FILE SECURITY · MARS SLF

Stop content-borne threats
before the file ever opens.

Wherever a file enters your network — cross-network transfer, document repository, web upload — SLF disarms non-executable document attacks at the point of ingress, before anyone clicks.

  • Cross-network transfer
  • Document repository
  • Web upload
  • CDR
SLF file security product illustration
APPLICATION · 01

Where SLF fits

SLF inserts inline only at the points where files enter from outside. Internal systems stay untouched — the MARS engine engages only at the moment of file ingress.

01

Cross-network file transfer

Inline analysis behind the network gateway for every file entering the internal network. Compatible with regulated-industry network separation mandates.

02

Document repository

Pre-screens files before ECM or DRM storage. Only clean originals land in the central repository.

03

Web upload portals

Web application server (WAS) callback API integration for public-service, bidding, and procurement portals. Block, quarantine, or sanitize uploads in real time.

04

Government and finance

Integrates with mail server, file server, and SIEM over standard protocols. No changes to existing infrastructure.

05

Manufacturing and energy OT

Sits on the one-way data ingress into OT networks. Verified compatibility with industrial control environments.

06

Secure development networks

Pre-screens incoming source code and libraries. Asynchronous queue processing keeps developers moving.

CAPABILITY · 02

Automated reverse engineering catches
unknown threats before they execute.

The MARS engine reverse-engineers the binary structure of non-executable files. It covers the three blind spots execution-based analysis misses — sandbox evasion, time-delayed triggers, and user-action triggers.

F.01

MARS reverse-engineering analysis

Identifies threats by disassembling the binary structure — without executing the file. Catches all three execution blind spots — sandbox evasion, time-delayed triggers, user-action triggers — and surfaces the document-borne threats sandboxes miss in HWP (Hangul Word Processor, Korea's standard document format), PDF, DOCX, and image files.

  • Sandbox-evasion and conditional-trigger detection
  • Structural disassembly across OOXML, embedded OLE, and archive headers
  • 10–20x faster than sandbox processing
F.02

CDR sanitization option

Strips macros, scripts, embedded OLE objects, and malicious links, then reassembles the document with the original layout preserved. Users receive a familiar file — minus the executable threat surface.

  • 309+ file formats sanitized
  • Original readability and formatting preserved
  • 34 ms per file average · no workflow impact
F.03

Inline transparent bridge

Sits behind the existing network gateway, mail server, or WAS in transparent mode. No routing, IP, or DNS changes; automatic bypass on failure eliminates the business-disruption risk.

  • Zero existing-infrastructure changes
  • Active-active HA with automatic bypass standard
  • ICAP, SMTP, REST, Syslog, and CEF integration
F.04

ConTI threat intelligence loop

Threats detected by SLF feed back into the ConTI platform, run through the KT AI pipeline, and redeploy as signatures and rulesets to every customer environment.

  • Automatic detection-data feedback loop
  • 50+ new threats learned per day (KT AI)
  • Offline signature distribution for air-gapped networks
ARCHITECTURE · 03

Zero changes to your infrastructure — standard inline deployment.

Inserted in transparent mode between external and internal networks. Traffic passes through unchanged — no routing, IP, or DNS modifications — while SLF inspects every file.

External → SLF → Internal DIAGRAM · INLINE TRANSPARENT
EXTERNAL Email ingress SMTP / M365 Web upload Public-service portal Cross-network transfer One-way SECULETTER SLF SLF Gateway MARS engine · reverse engineering Block malicious Block and log Pass clean Pass-through CDR sanitization Optional INTERNAL · UNCHANGED Internal file server EFS / NAS Document repository ECM / DRM SIEM / SOC Splunk · QRadar
  • Block malicious — logged and quarantined
  • Pass clean — 12-second average analysis
  • CDR option — sanitized and delivered
SPECIFICATION · 04

Third-party validated detection performance.

Figures pulled from the TTA GS Grade 1 benchmark test (200,000-file run) and field averages across 100+ deployments. Every number traces back to the source test report.

Throughput 49,000–315,000 files/day (HA configuration)
Avg. analysis time 12.027 seconds (TTA GS Grade 1 benchmark · 200,000-file run)
Supported formats 309+ formats (HWP, PDF, DOCX, XLSX, PPTX, images, archives, and more)
Sanitization speed 34 ms per file average (SLCDR option)
Deployment On-premises appliance (2U) · HA active-active
Integration ICAP · SMTP · REST · Syslog · CEF · SAML 2.0
Certifications 100% APT detection (Korea Internet & Security Agency benchmark) · TTA GS Grade 1 · Common Criteria EAL2 · Korea public-procurement listed · designated innovative procurement item
Analyst recognition Featured in Gartner CDR research as a Representative Vendor
Download solution brief (PDF)
REFERENCE · 05

File security trusted by leading institutions in government, finance, and defense.

National Health Insurance Service (NHIS)

Processes 100,000 public-service portal attachments per day. WAS callback API integration keeps the false-positive rate under 0.1%.

Ministry of Science and ICT (MSIT)

Standard secure-transfer segment for cross-network file flow at a national ministry. Cleared regulator security suitability review.

Daishin Securities

Inline mail and file-server security for a finance environment. ConTI feedback loop blocks new variants before they spread.

POC · BENCHMARK READY IN 3 DAYS

Document security.
See it for yourself.

Run a benchmark with your own files and samples. Deploys inline without changes to your existing infrastructure—results report typically within 3 days.

NDA upfront Government procurement approved Deployed across national ministries Common Criteria EAL2 certified