--- id: P-REINFORCE-AUTO-WIKI-SEC-001 category: Dev confidence_score: 0.95 tags: [security, dast, runtime-testing, automation, ci-cd, p-reinforce] last_reinforced: 2026-05-01 --- # [[DAST (Dynamic Application Security Testing)|DAST (Dynamic Application Security Testing]] ## ๐Ÿ“Œ ํ•œ ์ค„ ํ†ต์ฐฐ (The Karpathy Summary) > "์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์‹คํ–‰๋˜๋Š” ๋Ÿฐํƒ€์ž„ ํ™˜๊ฒฝ์—์„œ ํ•ด์ปค์˜ ๊ณต๊ฒฉ์„ ๋ชจ๋ฐฉํ•˜์—ฌ ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ์˜ ์œ„ํ˜‘์„ ๊ฒ€์ฆํ•จ์œผ๋กœ์จ, ๋ฐฐํฌ ํ›„(Post-deployment) ๋ณด์•ˆ์˜ ๊ณต๋ฐฑ์„ ๋ฉ”์šฐ๋Š” ๋™์  ๋ณด์•ˆ ์Šค์บ๋‹ ์ž๋™ํ™” ๊ณ„์ธต." ## ๐Ÿ“– ๊ตฌ์กฐํ™”๋œ ์ง€์‹ (Synthesized Content) DAST๋Š” ๋ผ์ด๋ธŒ ํ™˜๊ฒฝ์—์„œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋ณด์•ˆ ์ƒํƒœ๋ฅผ ์ ๊ฒ€ํ•˜๋Š” ํ•ต์‹ฌ ๊ธฐ์ˆ ์ž…๋‹ˆ๋‹ค. 1. **๋Ÿฐํƒ€์ž„ ๋ณด์•ˆ ๊ฒ€์ฆ**: * ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์•„๋‹Œ ์‹คํ–‰ ์ค‘์ธ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋Œ€์ƒ์œผ๋กœ ์™ธ๋ถ€ ๊ณต๊ฒฉ์„ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ํ•ฉ๋‹ˆ๋‹ค. * ์‹ค์ œ ์šด์˜ ํ™˜๊ฒฝ์—์„œ๋งŒ ๋ฐœ๊ฒฌ๋˜๋Š” ์„ค์ • ์˜ค๋ฅ˜๋‚˜ ๋™์  ์ทจ์•ฝ์ (์˜ˆ: ์„ธ์…˜ ํ•˜์ด์žฌํ‚น, ์ธํ”„๋ผ ๋ณด์•ˆ ๋“ฑ)์„ ํฌ์ฐฉํ•ฉ๋‹ˆ๋‹ค. 2. **CI/CD ํŒŒ์ดํ”„๋ผ์ธ ํ†ตํ•ฉ**: * ๋ฐฐํฌ ๋‹จ๊ณ„์— ์ž๋™ํ™”๋œ ์Šค์บ๋„ˆ๋กœ ํ†ตํ•ฉ๋˜์–ด ์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์„ ์„ ์ œ์ ์œผ๋กœ ํ•„ํ„ฐ๋งํ•ฉ๋‹ˆ๋‹ค. * ์ด๋ฅผ ํ†ตํ•ด ์ธ๊ฐ„ ๋ฆฌ๋ทฐ์–ด๋Š” ๋‹จ์ˆœ ํŒจํ„ด ํƒ์ƒ‰์—์„œ ๋ฒ—์–ด๋‚˜ ๊ณ ์ฐจ์›์  ๋กœ์ง ๋ฐ ์œ„ํ˜‘ ๋ชจ๋ธ๋ง์— ์ง‘์ค‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 3. **์ง€์†์ ์ธ ๋ณด์•ˆ ์ปค๋ฒ„๋ฆฌ์ง€**: * SAST(์ •์  ๋ถ„์„)๊ฐ€ ๋ฐฐํฌ ์ „ ๋ณด์•ˆ์„ ์ฑ…์ž„์ง„๋‹ค๋ฉด, DAST๋Š” ๋ฐฐํฌ ํ›„์˜ ๋™์ž‘์„ ์ง€์†์ ์œผ๋กœ ๊ฐ์‹œํ•˜์—ฌ ์ƒ๋ช…์ฃผ๊ธฐ ์ „์ฒด์˜ ๋ณด์•ˆ ๋ฌด๊ฒฐ์„ฑ์„ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค. ## โš ๏ธ ๋ชจ์ˆœ ๋ฐ ์—…๋ฐ์ดํŠธ (Contradictions & RL Update) - **์ฝ”๋“œ ์—ฐ๊ณ„์˜ ํ•œ๊ณ„**: DAST๋Š” ์™ธ๋ถ€ ๊ณต๊ฒฉ ๊ธฐ๋ฐ˜์ด๋ฏ€๋กœ ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•œ ์†Œ์Šค ์ฝ”๋“œ์˜ ์ •ํ™•ํ•œ ๋ผ์ธ ๋ฒˆํ˜ธ๋ฅผ ์ง€๋ชฉํ•˜๋Š” ๋ฐ ํ•œ๊ณ„๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ๋ณด์™„ํ•˜๊ธฐ ์œ„ํ•ด IAST์™€์˜ ๊ฒฐํ•ฉ์ด ๊ถŒ์žฅ๋ฉ๋‹ˆ๋‹ค. - **๋ถ€ํ•˜ ๋ฐ ์ตœ์ ํ™”**: ๋ผ์ด๋ธŒ ํ™˜๊ฒฝ ํ…Œ์ŠคํŠธ ์‹œ ์‹œ์Šคํ…œ ๋ถ€ํ•˜ ๋ฐ ๋ฐฐํฌ ์ง€์—ฐ(Bottleneck)์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ์Šคํ…Œ์ด์ง• ํ™˜๊ฒฝ์—์„œ์˜ ๋ณ‘๋ ฌ ์Šค์บ” ์ •์ฑ… ์ˆ˜๋ฆฝ์ด ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค. ## ๐Ÿ”— ์ง€์‹ ์—ฐ๊ฒฐ (Graph) - [[SAST (Static Application Security Testing)|SAST (Static Application Security Testing]]: ์ •์  ๋ถ„์„๊ณผ์˜ ์ƒํ˜ธ ๋ณด์™„์„ฑ. - [[IAST (Interactive Application Security Testing)|IAST (Interactive Application Security Testing]]: ๋Ÿฐํƒ€์ž„ ๋ฐ์ดํ„ฐ ํ๋ฆ„ ๋ถ„์„๊ณผ์˜ ๊ฒฐํ•ฉ. - Shift-Left Security: ๋ณด์•ˆ ํ…Œ์ŠคํŠธ์˜ ์กฐ๊ธฐ ๋„์ž… ์ „๋žต. - CI/CD Pipeline Integration: ์ž๋™ํ™” ์›Œํฌํ”Œ๋กœ์šฐ ๋‚ด์˜ ์œ„์น˜. - Threat Modeling: ์•„ํ‚คํ…์ฒ˜ ์ˆ˜์ค€์˜ ๋ณด์•ˆ ์„ค๊ณ„. ---