Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SBOM-VEX-Taint-Analysis — SBOM-to-VEX 파이프라인을 자동화하며, CVE를 분석하고, 악용 가능성을 추론하며, OWASP GenAI 지침을 준수하는 서명된 CycloneDX VEX 문서를 생성하는 안전한 다중 에이전트 AI 시스템입니다. | Kitploit
도구/GitHubGitHub/owasp/sbom-vex-taint-analysis
Vulnerability AnalysisSupply Chain SecurityPapers & ResearchLearning & EducationCurated ResourcesAI Security
GitHubowasp/sbom-vex-taint-analysis

SBOM-VEX-Taint-Analysis

SBOM-to-VEX 파이프라인을 자동화하며, CVE를 분석하고, 악용 가능성을 추론하며, OWASP GenAI 지침을 준수하는 서명된 CycloneDX VEX 문서를 생성하는 안전한 다중 에이전트 AI 시스템입니다.

저장소 보기
211개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SBOM → VEX 에이전트

SBOM에서 OWASP GenAI Security Project 지침에 따라 구축된 안전한 멀티 에이전트 AI 파이프라인을 사용하여 서명된 CycloneDX VEX 문서를 자동으로 생성합니다.

License: MIT OWASP CycloneDX AutoGen


문제점

SBOM을 생성하면 수백 개의 CVE가 드러납니다. 실제로 90% 이상이 특정 제품의 런타임 컨텍스트에서 악용 가능하지 않습니다. VEX(Vulnerability Exploitability eXchange) 문서가 없으면 모든 다운스트림 도구(Dependency-Track, 릴리스 게이트, 조달 체크리스트 등)가 거짓 양성에 빠져들게 됩니다.

자세한 기술 세부 사항 및 테스트 결과는 WIKI를 참조하세요.

수동 VEX 생성은 시간이 많이 소요되며 확장이 어렵습니다. 숙련된 분석가가 단일 구성 요소를 평가하는 데 몇 시간을 소비할 수 있습니다. 프로덕션 SBOM에는 500~2,000개의 구성 요소가 포함될 수 있습니다.

이 프로젝트는 해당 추론 파이프라인을 안전하게, 벤더 종속 없이, 모든 데이터를 인프라 내에 유지하면서 자동화합니다.

실제 동기: 2024년, 보안 연구원 Johanna Curiel이 Kubernetes Java Client를 분석하면서 바로 이 문제를 문서화했습니다(LinkedIn 기사). OSV 스캐너는 com.diffplug.spotless:spotless-maven-plugin 1.17.0에서 고위험 CVE를 몇 초 만에 식별했습니다. 해당 CVE가 not_affected(빌드 타임 플러그인, 런타임에 절대 실행되지 않음)임을 판단하는 데는 수 시간의 수동 분석이 필요했습니다. 이 프로젝트는 해당 추론 단계를 자동화합니다.


아키텍처

네 개의 보안 영역. 명시적 검증 없이는 어떤 경계도 넘지 않습니다.

root@kitploit:~
┌─────────────────────────────────────────────────────────────────┐
│  ZONE 1 — Input ingestion (no LLM)                              │
│  SBOM upload → Schema validate → Sanitise → SHA-256 audit hash  │
└────────────────────────────┬────────────────────────────────────┘
                             │
┌────────────────────────────▼────────────────────────────────────┐
│  ZONE 2 — OWASP guardrail middleware                            │
│  Prompt guard (LLM01) · Output filter (LLM02/05)                │
│  Agency limiter (LLM06) · Token budget (LLM10)                  │
└────────────────────────────┬────────────────────────────────────┘
                             │
┌────────────────────────────▼────────────────────────────────────┐
│  ZONE 3 — Multi-agent pipeline (AutoGen AgentChat)              │
│                                                                  │
│  Orchestrator                                                    │
│       ├── CVE Analyst       NVD v2 + OSV + EPSS per component   │
│       ├── Exploit Reasoner  Call graph · LLM reasoning · RAG    │
│       └── VEX Writer        CycloneDX 1.6 schema-validated      │
│                                                                  │
│  Vector store (Qdrant) — signed past VEX decisions              │
└────────────────────────────┬────────────────────────────────────┘
                             │
┌────────────────────────────▼────────────────────────────────────┐
│  ZONE 4 — Output, signing, audit                                │
│  Human-in-the-loop gate → cosign/GPG sign → audit log           │
└─────────────────────────────────────────────────────────────────┘

OWASP GenAI 규정 준수

이 프로젝트는 OWASP Top 10 for LLM Applications 2025 및 OWASP Top 10 for Agentic Applications 2026에 따라 설계되었습니다.

인-더-루프(Human-in-the-loop)는 필수입니다. 고심각도 CVE에 대한 VEX not_affected 문은 법적 효력을 지닌 주장입니다. 사람 검토자의 승인 없이는 어떤 VEX도 서명되지 않습니다. 이는 구성할 수 없습니다.


기술 스택

모든 것은 온프레미스에서 실행됩니다. 어떤 데이터도 인프라를 떠나지 않습니다.


요구 사항

하드웨어 (프로덕션):

  • 1× A100 80GB 또는 2× RTX 3090(VRAM 48GB 합계) (Qwen2.5-Coder-32B용)
  • 16GB 이상 시스템 RAM
  • 모델 가중치 및 벡터 저장소용 100GB 이상 SSD

하드웨어 (개발 / 작은 SBOM):

  • RAM 16GB인 모든 머신 — Ollama를 통해 llama3.1:8b 사용

소프트웨어:

  • Python 3.11+
  • Docker + Docker Compose
  • Node.js 18+ (cosign 도구용)

빠른 시작

1. 클론 및 설치

root@kitploit:~
git clone https://github.com/your-org/sbom-vex-agent
cd sbom-vex-agent
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt

2. LLM 백엔드 시작

root@kitploit:~
# Development — Ollama (CPU/GPU, any laptop)
ollama pull llama3.1
ollama serve

# Production — vLLM (GPU required)
python -m vllm.entrypoints.openai.api_server \
  --model Qwen/Qwen2.5-Coder-32B-Instruct \
  --gpu-memory-utilization 0.90 \
  --host 0.0.0.0 --port 8000

3. 지원 서비스 시작

root@kitploit:~
docker compose up -d   # starts Qdrant + PostgreSQL

4. SBOM에서 에이전트 실행

root@kitploit:~
python -m vex_agent analyse \
  --sbom path/to/your-sbom.cdx.json \
  --output path/to/output.vex.json

파이프라인은 다음을 수행합니다:

  1. SBOM 검증 및 정리
  2. 각 구성 요소에 대한 CVE 조회
  3. 악용 가능성 추론
  4. 초안 VEX를 사람 검토자에게 제시
  5. 승인 시 최종 문서 서명 및 출력

구성

.env.example을 .env로 복사하고 설정:

root@kitploit:~
# LLM backend
VLLM_BASE_URL=http://localhost:8000/v1    # or Ollama: http://localhost:11434/v1
LLM_MODEL=Qwen2.5-Coder-32B-Instruct     # or llama3.1 for dev

# Services
QDRANT_URL=http://localhost:6333
AUDIT_DB_URL=postgresql://audit:secret@localhost:5432/audit

# Signing (leave blank to use cosign keyless via Sigstore OIDC)
GPG_KEY_ID=                               # optional: use GPG instead

프로젝트 구조

root@kitploit:~
sbom-vex-agent/
├── vex_agent/
│   ├── ingest.py          # Zone 1: SBOM validation and sanitisation
│   ├── guardrails.py      # Zone 2: OWASP middleware (GuardrailedAgent)
│   ├── agents/
│   │   ├── orchestrator.py
│   │   ├── cve_analyst.py
│   │   ├── exploit_reasoner.py
│   │   └── vex_writer.py
│   ├── tools/
│   │   ├── nvd.py         # NVD v2 API client
│   │   ├── osv.py         # OSV.dev client
│   │   └── epss.py        # EPSS scoring
│   ├── vector_store.py    # Qdrant integration + provenance signing
│   ├── hitl.py            # Human-in-the-loop review gate
│   └── sign.py            # Zone 4: cosign / GPG signing
├── schemas/
│   ├── cdx-1.6.schema.json
│   └── cdx-1.6-vex.schema.json
├── tests/
├── docker-compose.yml
├── .env.example
└── requirements.txt

VEX 출력 형식

에이전트는 CycloneDX 1.6 VEX 문서를 생성합니다. 단일 구성 요소에 대한 예시 출력:

root@kitploit:~
{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "version": 1,
  "metadata": {
    "timestamp": "2026-04-26T10:00:00Z",
    "tools": [{ "name": "sbom-vex-agent", "version": "1.0.0" }]
  },
  "vulnerabilities": [
    {
      "id": "CVE-2021-37714",
      "affects": [{ "ref": "pkg:maven/com.diffplug.spotless/[email protected]" }],
      "analysis": {
        "state": "not_affected",
        "justification": "vulnerable_code_not_in_execute_path",
        "detail": "Plugin executes only at build time; not present in deployed runtime."
      }
    }
  ]
}

유효한 state 값: affected · not_affected · fixed · under_investigation

유효한 justification 값 (not_affected의 경우):

  • component_not_present
  • vulnerable_code_not_present
  • vulnerable_code_not_in_execute_path
  • vulnerable_code_cannot_be_controlled_by_adversary
  • inline_mitigations_already_exist

관련 자료

  • OWASP GenAI Security Project
  • OWASP Top 10 for LLM Applications 2025
  • OWASP Top 10 for Agentic Applications 2026
  • CycloneDX Specification
  • AutoGen AgentChat v0.4
  • OSV Vulnerability Database
  • EPSS Scoring API
  • Sigstore / cosign
  • Johanna Curiel — Analysing Supply Chain Vulnerabilities in the Kubernetes Java Client Using SBOM and Generating VEX (2024)

기여하기

기여를 환영합니다. 중요한 변경 사항의 경우 풀 리퀘스트를 제출하기 전에 이슈를 열어주세요.

보안 문제는 비공개로 보고해 주세요 — SECURITY.md 참조.


라이선스

MIT — LICENSE 참조.


OWASP GenAI Security Project에 따라 구축되었습니다. 공식 OWASP 프로젝트가 아닙니다.

도구 다운로드
OWASP 위험ID이 프로젝트에서의 완화
Prompt InjectionLLM01모든 SBOM 필드는 LLM 주입 전에 정리됨; 주입 패턴 블록리스트
Sensitive Info DisclosureLLM02모든 에이전트 출력에서 PII 스크러버; 내부 경로 필터
Improper Output HandlingLLM05서명 전 CycloneDX 스키마 검증; 실패 시 재시도
Excessive AgencyLLM06분석 중 읽기 전용 도구; 모든 CVSS ≥ 7.0 판결에 대한 HITL 게이트
System Prompt LeakageLLM07내부 정책을 시스템 프롬프트와 분리
Vector / Embedding WeaknessLLM08저장된 벡터 서명됨; 컨텍스트 주입 전 출처 확인
Unbounded ConsumptionLLM10MaxMessageTermination(20); 구성 요소별 토큰 예산; NVD 타임아웃
구성 요소도구비고
Agent orchestrationAutoGen AgentChat v0.4멀티 에이전트, 도구 사용, 메시지 훅
LLM (권장)Qwen2.5-Coder-32B최고의 구조화된 JSON + 보안 추론
LLM 서버vLLM (프로덕션) / Ollama (개발)OpenAI 호환 API
CVE 데이터NVD v2 API + OSV.dev + EPSS모두 무료, API 키 불필요
벡터 저장소Qdrant자체 호스팅, 과거 VEX 결정
임베딩all-MiniLM-L6-v2 (sentence-transformers)완전 로컬
SBOM 형식CycloneDX 1.4–1.7 (JSON/XML), SPDX 2.3/3.0수집 시 스키마 검증
VEX 출력CycloneDX 1.6 VEX서명 전 스키마 검증
서명cosign (Sigstore keyless)타임스탬프, 감사 로깅
감사 로그PostgreSQL (append-only, pgaudit)모든 에이전트 결정 기록