--- id: P-REINFORCE-SEC-SAST category: "10_Wiki/πŸ’‘ Topics/Security" confidence_score: 0.99 tags: [SAST, Security, SDLC, Code Analysis] last_reinforced: 2026-04-20 --- # SAST-(Static-Application-Security-Testing) (정적 λ³΄μ•ˆ ν…ŒμŠ€νŠΈ) ## πŸ“Œ ν•œ 쀄 톡찰 (The Karpathy Summary) > "μ½”λ“œλ₯Ό μ‹€ν–‰ν•˜κΈ°λ„ 전에 ꡬ멍을 찾아라." μ†Œν”„νŠΈμ›¨μ–΄ 개발 생λͺ… μ£ΌκΈ°(SDLC)의 κ°€μž₯ μ•žλ‹¨(Shift-Left)μ—μ„œ μ†ŒμŠ€ μ½”λ“œλ₯Ό μŠ€μΊ”ν•˜μ—¬ λ³΄μ•ˆ 취약점을 쑰기에 κ²©λ¦¬ν•˜λŠ” κΈ°μˆ μ΄λ‹€. ## πŸ“– κ΅¬μ‘°ν™”λœ 지식 (Synthesized Content) - **White-box Testing**: - ν”„λ‘œκ·Έλž¨μ˜ λ‚΄λΆ€ ꡬ쑰와 μ†ŒμŠ€ μ½”λ“œλ₯Ό λͺ¨λ‘ μ•Œκ³  μžˆλŠ” μƒνƒœμ—μ„œ μ§„ν–‰ν•˜λŠ” 뢄석. 데이터 흐름(Data Flow)κ³Ό μ œμ–΄ 흐름(Control Flow)을 μΆ”μ ν•œλ‹€. - **Vulnerability Coverage**: - SQL Injection, Cross-Site Scripting(XSS), Buffer Overflow λ“± 잘 μ•Œλ €μ§„ λ³΄μ•ˆ νŒ¨ν„΄(OWASP Top 10 λ“±)을 μžλ™μœΌλ‘œ κ°μ‹œν•œλ‹€. - **Shift-Left Security**: - 배포 ν›„(DAST)κ°€ μ•„λ‹ˆλΌ μ½”λ”© μ‹œμ (IDE 톡합)에 ν”Όλ“œλ°±μ„ μ£Όμ–΄, λ³΄μ•ˆ μˆ˜μ • λΉ„μš©μ„ μˆ˜μ‹­ λ°° 이상 μ ˆκ°ν•œλ‹€. ## ⚠️ λͺ¨μˆœ 및 μ—…λ°μ΄νŠΈ (RL Update) - SAST의 κ°€μž₯ 큰 적은 'μ˜€νƒ(False Positive)'이닀. μ‹€μ œλ‘œ μ•ˆμ „ν•˜μ§€λ§Œ μœ„ν—˜ν•˜λ‹€κ³  κ²½κ³ ν•˜λŠ” κ²½μš°κ°€ λ§Žμ•„ κ°œλ°œμžλ“€μ˜ ν”Όλ‘œλ„λ₯Ό 높인닀. 이λ₯Ό ν•΄κ²°ν•˜κΈ° μœ„ν•΄ μ΅œκ·Όμ—λŠ” AIκ°€ μ˜€νƒμ„ κ±ΈλŸ¬μ£ΌλŠ” 'AI-Driven SAST'κ°€ μ£Όλ₯˜λ‘œ 자리 작고 μžˆλ‹€. ## πŸ”— 지식 μ—°κ²° (Graph) - Related: Best-SAST-Tools-in-2026 , [[Deployment_Final_Gate|Deployment_Final_Gate]] - Foundation: [[Reliability_Safety_First|Reliability_Safety_First]]