본 연구는 소프트웨어 공급망 보안의 핵심 요소인 오픈소스 저장소의 안전성을 확보하기 위해, 정적 분석 도구와 대형 언어 모델(LLM)을 결합한 하이브리드 취약점 탐지 파이프라인을 제안하...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=A110411639
2026
Korean
530
학술저널
61-64(4쪽)
0
상세조회0
다운로드본 연구는 소프트웨어 공급망 보안의 핵심 요소인 오픈소스 저장소의 안전성을 확보하기 위해, 정적 분석 도구와 대형 언어 모델(LLM)을 결합한 하이브리드 취약점 탐지 파이프라인을 제안하...
본 연구는 소프트웨어 공급망 보안의 핵심 요소인 오픈소스 저장소의 안전성을 확보하기 위해, 정적 분석 도구와 대형 언어 모델(LLM)을 결합한 하이브리드 취약점 탐지 파이프라인을 제안하고 그 효율성을 실증적으로 평가한다. 기존 정적 분석 도구의 높은 False Positive 비율과 GitHub Search API 기반 타겟 선정의 비효율성을 개선하기 위해, LLM 기반 저장소 필터링 기법을 도입하고 CodeQL, SonarQube, Semgrep을 결합한 세 가지 분석 파이프라인을 구성하였다. 탐지 결과는 LLM과 인간 전문가의 협업 검증 과정을 거쳐 실제 취약점 여부(True Positive)와 보안 영향도를 평가하였으며, 일부 사례에서는 실제 운영 서비스에 영향을 미치는 보안 위협을 발견하여 책임 있는 제보(Responsible Disclosure) 절차까지 완료하였다. 본 연구는 자동화된 정적 분석, LLM 기반 분석 보조, 인간의 판단력을 결합한 협업 모델의 가능성을 제시하며, 오픈소스 보안 감사 자동화의 효율성과 한계를 함께 논의한다.
다국어 초록 (Multilingual Abstract)
This study proposes and empirically evaluates a hybrid vulnerability detection pipeline that combines static analysis tools with large language models (LLMs) to enhance the security of open-source repositories, a critical component of software supply ...
This study proposes and empirically evaluates a hybrid vulnerability detection pipeline that combines static analysis tools with large language models (LLMs) to enhance the security of open-source repositories, a critical component of software supply chain security. To address the high false-positive rates of conventional static analysis tools and the inefficiency of GitHub Search API–based target selection, we introduce an LLM-based repository filtering method and construct three analysis pipelines integrating CodeQL, SonarQube, and Semgrep. The detected results were validated through a collaborative verification process involving both LLMs and human experts to determine true positives and assess their security impact. In several cases, the study identified security threats affecting real-world production services and completed the responsible disclosure process accordingly. This research demonstrates the potential of a collaborative model that combines automated static analysis, LLM-assisted analysis, and human judgment, while also discussing the effectiveness and limitations of automating open-source security auditing.
목차 (Table of Contents)
물리적 설비 한계를 극복하는 AI 기반 제로 에너지 빌딩 구축 알고리즘 제안: 열에너지 데이터 시각화 및 시뮬레이션을 중심으로
AI와 LLM을 결합한 C/C++ 소스코드 취약점 탐지 시스템
리눅스 환경에서의 Configuration Drift 탐지 및 승인 기반 대응을 위한 보안 통제 메커니즘 연구
생성형 AI 도입에 따른 데이터 유출 방지(DLP) 기술 및 보안 거버넌스 동향 조사
Fluevogs Open-Source Footwear
Harvard University Bill TaylorGoodbye, textbooks; hello, open-source learning
TED Richard Baraniuk2014 이러닝 국제 콘퍼런스 : Utilizing Education System through Open Source: Using Columbia Case
한국교육학술정보원 In-Sik, YooSocial Constructivism and Open Source Software
Teachers TV Teachers TVTransactional Analysis and Communications
Teachers TV Teachers TV