--- id: P-REINFORCE-AUTO-WIKI-SEC-002 category: "10_Wiki/๐Ÿ’ก Topics/Security & Reliability" confidence_score: 0.95 tags: [security, sast, static-analysis, shift-left, code-review, p-reinforce] last_reinforced: 2026-05-01 --- # [[SAST (Static Application Security Testing)|SAST (Static Application Security Testing]] ## ๐Ÿ“Œ ํ•œ ์ค„ ํ†ต์ฐฐ (The Karpathy Summary) > "์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‹คํ–‰ํ•˜์ง€ ์•Š๊ณ  ์†Œ์Šค ์ฝ”๋“œ ์ž์ฒด๋ฅผ ๋ถ„์„ํ•˜์—ฌ ๊ฒฐํ•จ์„ ์ฐพ์•„๋‚ด๋Š” ์ฒซ ๋ฒˆ์งธ ๋ฐฉ์–ด์„ ์œผ๋กœ, ๋ณด์•ˆ ๊ฒฐํ•จ ์ˆ˜์ • ๋น„์šฉ์„ ์ตœ์†Œํ™”ํ•˜๋Š” '์‹œํ”„ํŠธ ๋ ˆํ”„ํŠธ(Shift-Left)' ์ „๋žต์˜ ํ•ต์‹ฌ ์—”์ง„." ## ๐Ÿ“– ๊ตฌ์กฐํ™”๋œ ์ง€์‹ (Synthesized Content) SAST๋Š” ๊ฐœ๋ฐœ ์ดˆ๊ธฐ ๋‹จ๊ณ„์—์„œ ๋ณด์•ˆ ๋ฌด๊ฒฐ์„ฑ์„ ํ™•๋ณดํ•˜๊ธฐ ์œ„ํ•œ ์ •์  ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. 1. **์ •์  ๋ถ„์„ ๋ฉ”์ปค๋‹ˆ์ฆ˜**: * ์†Œ์Šค ์ฝ”๋“œ์˜ ๊ตฌ๋ฌธ(AST)๊ณผ ๋…ผ๋ฆฌ ๊ตฌ์กฐ๋ฅผ ์Šค์บ”ํ•˜์—ฌ ์ทจ์•ฝํ•œ ํŒจํ„ด(์˜ˆ: OWASP Top 10)์„ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค. * ์ทจ์•ฝ์ ์˜ ์ •ํ™•ํ•œ ๋ผ์ธ ๋ฒˆํ˜ธ๋ฅผ ์ œ๊ณตํ•˜์—ฌ ๊ฐœ๋ฐœ์ž๊ฐ€ ์ฆ‰๊ฐ์ ์œผ๋กœ ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. 2. **๋ฆฌ๋ทฐ์–ด์˜ ์ธ์ง€ ์—๋„ˆ์ง€ ๋ณด์กด**: * ์ธ์ ์…˜ ๊ฒฐํ•จ์ด๋‚˜ ๊ธฐ์ดˆ์ ์ธ ๋ณด์•ˆ ์‹ค์ˆ˜๋ฅผ ๊ธฐ๊ณ„๊ฐ€ ์„ ๋ณ„ํ•จ์œผ๋กœ์จ, ์ธ๊ฐ„ ๋ฆฌ๋ทฐ์–ด๋Š” ์•„ํ‚คํ…์ฒ˜ ์˜๋„์™€ ๋น„์ฆˆ๋‹ˆ์Šค ๋กœ์ง ๊ฒ€ํ† ์— ์ง‘์ค‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 3. **์กฐ๊ธฐ ๋ฐœ๊ฒฌ (Shift-Left)**: * ์ฝ”๋“œ ์ž‘์„ฑ ๋ฐ PR ๋‹จ๊ณ„์—์„œ ์ฆ‰์‹œ ์œ„ํ˜‘์„ ๊ฐ์ง€ํ•˜์—ฌ, ํ”„๋กœ๋•์…˜ ๋ฐฐํฌ ํ›„ ๋ฐœ์ƒํ•˜๋Š” ๋ง‰๋Œ€ํ•œ ์ˆ˜์ • ๋น„์šฉ์„ ์˜ˆ๋ฐฉํ•ฉ๋‹ˆ๋‹ค. ## โš ๏ธ ๋ชจ์ˆœ ๋ฐ ์—…๋ฐ์ดํŠธ (Contradictions & RL Update) - **์˜คํƒ(False Positives) ๊ด€๋ฆฌ**: ํŒจํ„ด ๋งค์นญ์— ์˜์กดํ•˜๋ฏ€๋กœ ์‹ค์ œ ์œ„ํ˜‘์ด ์•„๋‹Œ ์ฝ”๋“œ๋„ ์œ„ํ—˜์œผ๋กœ ๋ถ„๋ฅ˜ํ•˜๋Š” ๋…ธ์ด์ฆˆ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋ฆฌ๋ทฐ ํŒ€์˜ ์ฃผ๊ด€์  ๊ฒ€์ฆ(Validation) ์ •์ฑ…์œผ๋กœ ๋ณด์™„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. - **๋งฅ๋ฝ ์ธ์ง€์˜ ํ•œ๊ณ„**: ๋น„์ฆˆ๋‹ˆ์Šค ๋กœ์ง์ด๋‚˜ ๋Ÿฐํƒ€์ž„ ํ™˜๊ฒฝ ์„ค์ •(๋„คํŠธ์›Œํฌ ๋“ฑ)์— ์˜ํ•œ ๋™์  ์ทจ์•ฝ์ ์€ ํƒ์ง€ํ•  ์ˆ˜ ์—†์œผ๋ฏ€๋กœ DAST/IAST์™€์˜ ๋ณ‘ํ–‰์ด ํ•„์ˆ˜์ž…๋‹ˆ๋‹ค. ## ๐Ÿ”— ์ง€์‹ ์—ฐ๊ฒฐ (Graph) - [[DAST (Dynamic Application Security Testing)|DAST (Dynamic Application Security Testing]]: ๋™์  ๋ถ„์„๊ณผ์˜ ๋ณด์™„์  ๊ด€๊ณ„. - Shift-Left Security: ๋ณด์•ˆ์˜ ์กฐ๊ธฐ ๋„์ž… ์ฒ ํ•™. - CI/CD Pipeline Integration: ํ’ˆ์งˆ ๊ฒŒ์ดํŠธ(Quality Gate)๋กœ์„œ์˜ ๊ตฌํ˜„. - [[Automated Code Analysis (แ„Œแ…กแ„ƒแ…ฉแ†ผแ„’แ…ชแ„ƒแ…ฌแ†ซ แ„แ…ฉแ„ƒแ…ณ แ„‡แ…ฎแ†ซแ„‰แ…ฅแ†จ)|Automated Code Analysis]]: ๋ฆฐํŒ… ๋ฐ ์ •์  ๋ถ„์„ ๋„๊ตฌ๊ตฐ. - SCA (Software Composition Analysis: ์™ธ๋ถ€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ณด์•ˆ ๊ฒ€์ฆ์œผ๋กœ์˜ ํ™•์žฅ. ---