--- id: P-REINFORCE-AUTO-205541 category: "[[10_Wiki/πŸ’‘ Topics/AI]]" confidence_score: 0.90 tags: [auto-reinforced] last_reinforced: 2026-04-20 github_commit: "[P-Reinforce] Continuous Worker - SAST" --- # [[SAST]] ## πŸ“Œ ν•œ 쀄 톡찰 (The Karpathy Summary) > SAST(Static Application Security Testing, 정적 μ• ν”Œλ¦¬μΌ€μ΄μ…˜ λ³΄μ•ˆ ν…ŒμŠ€νŠΈ)λŠ” μ• ν”Œλ¦¬μΌ€μ΄μ…˜μ„ μ‹€ν–‰ν•˜μ§€ μ•Šκ³  μ†ŒμŠ€ μ½”λ“œ, λ°”μ΄νŠΈμ½”λ“œ λ˜λŠ” λ°”μ΄λ„ˆλ¦¬λ₯Ό μ •μ μœΌλ‘œ λΆ„μ„ν•˜μ—¬ λ³΄μ•ˆ 취약점을 μ°Ύμ•„λ‚΄λŠ” ν™”μ΄νŠΈλ°•μŠ€ ν…ŒμŠ€νŠΈ κΈ°λ²•μž…λ‹ˆλ‹€ [1-3]. 개발 초기 단계인 IDEλ‚˜ CI/CD νŒŒμ΄ν”„λΌμΈμ— ν†΅ν•©λ˜μ–΄ 결함을 사전에 ν•΄κ²°ν•˜λŠ” 'μ‹œν”„νŠΈ λ ˆν”„νŠΈ(Shift-left)' λ³΄μ•ˆ μ ‘κ·Όλ²•μ˜ 핡심적인 역할을 μˆ˜ν–‰ν•©λ‹ˆλ‹€ [4-7]. μ΅œκ·Όμ—λŠ” 높은 μ˜€νƒλ₯ (False Positive)κ³Ό λ¬Έλ§₯ νŒŒμ•…μ˜ ν•œκ³„λ₯Ό κ·Ήλ³΅ν•˜κΈ° μœ„ν•΄ λ¨Έμ‹ λŸ¬λ‹(ML)κ³Ό λŒ€κ·œλͺ¨ μ–Έμ–΄ λͺ¨λΈ(LLM)을 κ²°ν•©ν•œ AI 기반 SAST둜 μ§„ν™”ν•˜μ—¬ λ”μš± μ •ν™•ν•œ 탐지와 μžλ™ μˆ˜μ •(Auto-fix) κΈ°λŠ₯을 μ œκ³΅ν•˜κ³  μžˆμŠ΅λ‹ˆλ‹€ [8-10]. ## πŸ“– κ΅¬μ‘°ν™”λœ 지식 (Synthesized Content) λ³Έλ¬Έ ꡬ쑰화 μž‘μ—… 쀑... ## ⚠️ λͺ¨μˆœ 및 μ—…λ°μ΄νŠΈ (Contradictions & RL Update) - **κ³Όκ±° λ°μ΄ν„°μ™€μ˜ 좩돌:** μžλ™ν™” 엔진에 μ˜ν•΄ λ§€ν•‘λœ μ§€μ‹μœΌλ‘œ, μΆ”ν›„ μ •λ°€ 검증 ν•„μš”. - **μ •μ±… λ³€ν™”:** AI λΆ„μ•Όμ˜ μžλ™ μžμ‚°ν™” μˆ˜ν–‰. ## πŸ”— 지식 μ—°κ²° (Graph) - **Related Topics:** [[DAST]], [[SCA]], [[IAST]], [[Shift-Left]], [[False Positives]] - **Projects/Contexts:** [[CI/CD Pipeline Integration]], [[Snyk Code]], [[Corgea]], [[Checkmarx]], [[SonarQube]] - **Contradictions/Notes:** μžλ™ν™”λœ SAST λ„κ΅¬λŠ” μ½”λ“œ 기반의 νŒ¨ν„΄ 맀칭에 λΉ λ₯΄κ³  μΌκ΄€λ˜μ§€λ§Œ, λ³΅μž‘ν•œ λΉ„μ¦ˆλ‹ˆμŠ€ 둜직과 μ•„ν‚€ν…μ²˜ νŠΈλ ˆμ΄λ“œμ˜€ν”„λ₯Ό μ΄ν•΄ν•˜μ§€ λͺ»ν•˜λ―€λ‘œ, μ™„λ²½ν•œ λ³΄μ•ˆκ³Ό μ½”λ“œ ν’ˆμ§ˆ 확보λ₯Ό μœ„ν•΄μ„œλŠ” 인간 κ°œλ°œμžκ°€ 직접 μˆ˜ν–‰ν•˜λŠ” μˆ˜λ™ μ½”λ“œ 리뷰(Manual Code Review)λ₯Ό λ°˜λ“œμ‹œ 병행해야 ν•œλ‹€κ³  κ°•μ‘°λ©λ‹ˆλ‹€ [16, 26-28]. --- *Last updated: 2026-04-19* - Raw Source: [[00_Raw/2026-04-20/SAST.md]] ---