--- id: SEC-INPUT-001 category: "10_Wiki/πŸ’‘ Topics/AI" confidence_score: 1.0 tags: [security, software-engineering, input-validation, data-integrity, defensive-programming] last_reinforced: 2026-04-26 --- # Input Validation Strategies (μž…λ ₯ 검증 μ „λž΅) ## πŸ“Œ ν•œ 쀄 톡찰 (The Karpathy Summary) > "λͺ¨λ“  μ™ΈλΆ€ μž…λ ₯을 잠재적 μœ„ν˜‘μœΌλ‘œ κ°„μ£Όν•˜κ³ , μ‹œμŠ€ν…œμ˜ κ²½κ³„μ—μ„œ λ°μ΄ν„°μ˜ ν˜•μ‹κ³Ό μ˜λ„λ₯Ό μ—„κ²©νžˆ μ‹¬μ‚¬ν•˜λΌ" β€” μ‚¬μš©μžλ‚˜ λ‹€λ₯Έ μ‹œμŠ€ν…œμœΌλ‘œλΆ€ν„° μœ μž…λ˜λŠ” 데이터가 κΈ°λŒ€ν•˜λŠ” ν˜•μ‹, 길이, νƒ€μž…μ— λ§žλŠ”μ§€ ν™•μΈν•˜μ—¬ μΈμ μ…˜ κ³΅κ²©μ΄λ‚˜ λŸ°νƒ€μž„ 였λ₯˜λ₯Ό μ›μ²œ μ°¨λ‹¨ν•˜λŠ” 방어적 섀계 μ „λž΅. ## πŸ“– κ΅¬μ‘°ν™”λœ 지식 (Synthesized Content) - **μΆ”μΆœλœ νŒ¨ν„΄:** "Never Trust User Input" β€” μ‹ λ’°ν•  수 μ—†λŠ” 경계(Trust Boundary)λ₯Ό ν†΅κ³Όν•˜λŠ” λͺ¨λ“  데이터에 λŒ€ν•΄ ν™”μ΄νŠΈλ¦¬μŠ€νŠΈ 기반의 검증을 μˆ˜ν–‰ν•˜κ³ , μ•ˆμ „ν•œ ν˜•νƒœλ‘œ λ³€ν™˜(Sanitization)ν•˜μ—¬ μ‹œμŠ€ν…œ λ‚΄λΆ€λ‘œ μ „λ‹¬ν•˜λŠ” 필터링 νŒ¨ν„΄. - **μ£Όμš” μ „λž΅:** - **Type Checking:** κΈ°λŒ€ν•˜λŠ” 데이터 νƒ€μž…(String, Int λ“±) μ—¬λΆ€ 확인. - **Range & Format Validation:** 숫자의 λ²”μœ„λ‚˜ 이메일/λ‚ μ§œ λ“±μ˜ μ •κ·œμ‹ νŒ¨ν„΄ κ²€μΉ˜. - **Whitelisting:** ν—ˆμš©λœ κ°’μ˜ λͺ©λ‘ μ™Έμ—λŠ” λͺ¨λ‘ κ±°λΆ€ (κ°€μž₯ μ•ˆμ „ν•œ 방식). - **Sanitization:** μœ„ν—˜ν•œ 특수 문자(<, >, ' λ“±)λ₯Ό μ•ˆμ „ν•œ 문자둜 μΉ˜ν™˜. - **의의:** SQL Injection, XSS, Buffer Overflow λ“± 고질적인 μ†Œν”„νŠΈμ›¨μ–΄ λ³΄μ•ˆ μ·¨μ•½μ μ˜ 80% 이상을 μ˜ˆλ°©ν•  수 μžˆλŠ” κ°€μž₯ 기본적이고 κ°•λ ₯ν•œ λ³΄μ•ˆ μˆ˜λ‹¨. ## ⚠️ λͺ¨μˆœ 및 μ—…λ°μ΄νŠΈ (Contradictions & RL Update) - **κ³Όκ±° λ°μ΄ν„°μ™€μ˜ 좩돌:** λ‹¨μˆœν•œ 문법적 κ²€μ¦μ—μ„œ λ²—μ–΄λ‚˜, μ΄μ œλŠ” LLM μ‹œλŒ€μ— 맞좰 'ν”„λ‘¬ν”„νŠΈ μΈμ μ…˜'κ³Ό 같은 의미둠적 μœ„ν˜‘(Semantic Threat)을 κ°μ§€ν•˜κ³  μ°¨λ‹¨ν•˜λŠ” μ§€λŠ₯ν˜• 검증이 ν•„μˆ˜μ μœΌλ‘œ μš”κ΅¬λ¨. - **μ •μ±… λ³€ν™”:** Antigravity ν”„λ‘œμ νŠΈλŠ” μ—μ΄μ „νŠΈμ—κ²Œ μ „λ‹¬λ˜λŠ” λͺ¨λ“  μ‚¬μš©μž λ°œν™”μ™€ μ™ΈλΆ€ 파일 데이터λ₯Ό μ²˜λ¦¬ν•˜κΈ° μ „, λ³΄μ•ˆ μŠ€μΊ” 및 ν˜•μ‹ 검증 λ ˆμ΄μ–΄λ₯Ό κ±°μΉ˜λ„λ‘ κ°•μ œν•¨. ## πŸ”— 지식 μ—°κ²° (Graph) - [[Software-Architecture-Patterns|Software-Architecture-Patterns]], Cloud-Security-Mastery, Data-Privacy-Foundations, [[LLM-Security-and-Safety|LLM-Security-and-Safety]] - **Raw Source:** 10_Wiki/Topics/AI/Input-Validation-Strategies.md