Avaliação de Cobertura de SAST e LLM em Plataformas de Blockchain Permissionada para Supply Chain Automotiva com base no OWASP

  • Glauco Scheffel UDESC
  • Luiz Camargo UDESC
  • Gilson Sohn Junior UDESC
  • Pedro de Souza UDESC
  • Charles Miers UDESC
  • Marcos A. Simplicio Junior USP
  • Maurício Pillon UDESC / USP

Resumo


As plataformas de blockchain (BC) permissionadas aplicadas à cadeia de suprimentos ampliam a superfície de ataque ao combinarem contratos inteligentes, APIs, identidades e componentes off-chain, o que exige abordagens de análise de segurança que vão além dos padrões convencionais. Este trabalho investiga em que medida ferramentas tradicionais de SAST cobrem os riscos dessas plataformas e quais lacunas emergem diante de uma análise contextual assistida por LLM, tendo como referência o OWASP Top 10:2025. A avaliação foi conduzida em duas plataformas industriais baseadas em Hyperledger Fabric HERMES e MoVChain, combinando SonarCloud, Semgrep e análise assistida por LLM. Foram identificados 124 achados em código próprio, organizados em 25 categorias consolidadas de risco, com baixa sobreposição entre as fontes (apenas 12%). Os resultados evidenciam que a combinação dessas abordagens, com validação humana, fortalece a cobertura em processos de desenvolvimento seguros para ambientes industriais com blockchains permissionadas.

Referências

Agam, M. (2026). OWASP Security Skill for Claude Code. [link]. Acesso em: 17 maio 2026.

Aideyan, I., Pesé, M., and Brooks, R. (2025). Advancing automotive software supply chain security: A blockchain-reproducible build approach. In 2025 NDIA Michigan Chapter Ground Vehicle Systems Engineering and Technology Symposium, Novi, Michigan, United States.

Alsadi, M., Arshad, J., Ali, J., Prince, A., and Shishank, S. (2023). Trucert: Blockchain-based trustworthy product certification within autonomous automotive supply chains. Computers and Electrical Engineering, 109:108738.

Ameen, M. R., Alam, M. T. U., and Islam, A. (2026). QASecClaw: A multi-agent llm approach for false positive reduction in static application security testing.

Anthropic (2026). Introducing Claude Opus 4.7. [link]. Acesso em: 17 maio 2026.

Budiyanto, S., Silalahi, L. M., Hakim, A. R., Hamid, A., and Hanafi, D. (2024). Vulnerability analysis on internet of things (iot) networks using raspberry pi and open web application security project (owasp). In 2024 FORTEI-International Conference on Electrical Engineering (FORTEI-ICEE), pages 58–63.

Deshapriya, L., Licorish, S. A., and Woodford, B. J. (2026). Understanding warnings generated by pmd and sonarqube, their rules and compliance to established coding standards. Science of Computer Programming, 252.

Fasha, M., Rub, F. A., Matar, N., Sowan, B., Al Khaldy, M., and Barham, H. (2024). Mitigating the owasp top 10 for large language models applications using intelligent agents. In 2024 2nd International Conference on Cyber Resilience (ICCR), pages 1–9.

Halder, S., Saxena, S., Shrish, K. K., and M, T. (2026). SecLens: Role-specific evaluation of llms for security vulnerability detection.

Hopfer, K. B., Junior, G. S., Camargo, L. C., and Pillon, M. A. (2026). HERMES: Impacto de algoritmos de congestionamento no processo de certificação de origem. In Anais do ERAD/RS 2026 – Fórum de Iniciação Científica e Pós-Graduação, Bagé, RS, Brasil.

International Organization for Standardization (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection – Information security management systems – Requirements. Technical Report ISO/IEC 27001:2022, International Organization for Standardization, Geneva, Switzerland. Acesso em: 17 maio 2026.

Li, P., Li, S., Ding, M., Yu, J., Zhang, H., Zhou, X., and Li, J. (2022). A vulnerability detection framework for hyperledger fabric smart contracts based on dynamic and static analysis. In Proceedings of the International Conference on Evaluation and Assessment in Software Engineering 2022, EASE 2022, pages 366–374, New York, NY, USA. Association for Computing Machinery.

Liang, W., Liu, Y., Yang, C., Xie, S., Li, K., and Susilo, W. (2024). On identity, transaction, and smart contract privacy on permissioned and permissionless blockchain: A comprehensive survey. ACM Computing Surveys, 56(12).

Liao, Y., Kong, X., Yin, L., Zhang, G., Wang, K., Cao, Y., and Sun, X. (2026). Ds-duc: A method for data usage control in automotive supply chain based on industrial data space. Results in Engineering, 29.

López, A. E., Pinilla, M. A., and Mora, H. R. C. (2025). Risk-based security hardening in iot systems using owasp and cyberattack simulations. In 2025 IEEE Ninth Ecuador Technical Chapters Meeting (ETCM), pages 1–6. IEEE.

Nishikawa-Pacher, A. (2022). Research questions with pico: a universal mnemonic. Publications, 10(3):21.

Nowak, S. (2025). CORRECTION: Automating origin calculations: key considerations for manufacturers with complex supply chains. World Customs Journal, 19(2):138–156.

Oka, D. K. (2021). Building Secure Cars: Assuring the Automotive Software Development Lifecycle. John Wiley & Sons, Hoboken, NJ, USA.

OWASP Foundation (2025). OWASP Top 10:2025. [link]. Acesso em: 17 maio 2026.

Scheffel, G., Camargo, L., Sohn Junior, G., Souza, P. H. S. d., Miers, C. C., Simplicio Junior, M. A., and Pillon, M. A. (2026). UDESC-BCMX-SBSeg: Reports and supplementary material. [link]. Acesso restrito, disponível mediante solicitação aos autores.

Semgrep (2026). View findings in Semgrep AppSec Platform. [link]. Acesso em: 17 maio 2026.

SonarSource (2026). SonarQube Cloud: Scalable AI Code Verification. [link]. Acesso em: 17 maio 2026.

Souza, P. H. S. d., Zachêo, J. V., Miers, C. C., Simplicio Jr., M. A., Koslovski, G. P., and Pillon, M. A. (2026). MoVChain: ESG traceability platform for the automotive supply chain. In Proceedings of the 40th International Conference on Advanced Information Networking and Applications (AINA-2026), Wellington, New Zealand. Springer. April 8–10, 2026.
Publicado
01/09/2026
SCHEFFEL, Glauco; CAMARGO, Luiz; SOHN JUNIOR, Gilson; SOUZA, Pedro de; MIERS, Charles; SIMPLICIO JUNIOR, Marcos A.; PILLON, Maurício. Avaliação de Cobertura de SAST e LLM em Plataformas de Blockchain Permissionada para Supply Chain Automotiva com base no OWASP. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 887-894. DOI: https://doi.org/10.5753/sbseg_estendido.2026.29081.

Artigos mais lidos do(s) mesmo(s) autor(es)