ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
8.7 KiB
8.7 KiB
Changelog
한국어 · English · 中文 (upstream original)
This document records the changes that the ARTEX Korean edition (this fork) adds on top of the upstream repository. The format follows Keep a Changelog.
The upstream ARTEX project's per-version release history (0.3.x and earlier) and contributor list are preserved verbatim in Chinese in CHANGELOG.zh.md. As with README.zh.md, the original text is kept unchanged so that it stays easy to compare against upstream changes. The detailed content and rationale for each change can be found in the repository's commit history.
[Unreleased] · Korean edition changes
Localization (i18n)
- Forced user-facing output into Korean. The benchmarked agent's behavioral-instruction body (the "brain") is left in its original language to preserve performance, and a code-level fixed segment (
langDirective) instructs the agent to write only the user-facing output (vulnerability reports, fact summaries, final summaries, chat replies) in Korean. Commands, payloads, code, and raw logs are kept in their original form. - Translated the web UI into Korean. Introduced
next-intlinto the Next App Router and split the strings intoweb/messages/ko.jsonandweb/messages/zh.json. The original Chinese is preserved inzh.jsonso that it can be compared against upstream updates. Screen strings for the dashboard, vulnerabilities, chat, notification delivery, interception, LLM settings, and more were translated into Korean. - Translated the server API's user-facing errors and responses into Korean. HTTP error and response text that is returned to the browser was replaced with Korean. Text that feeds back into the agent brain as input, however, was kept in its original language to prevent benchmark drift, and the reasoning behind each such decision is recorded in the repository's working documents.
- Reorganized the documentation in Korean. Created a Korean
README.md, kept an EnglishREADME.en.mdalongside it, and preserved the original Chinese asREADME.zh.md.
Defense and detection resources
- Added a defense and detection guide. A Korean guide (
docs/defense-ko.md) and an English version with the same content (docs/defense-en.md) that cover how an autonomous AI attack differs from a traditional scanner, the fingerprints (IoCs) a defender can observe, entry points and hardening, detection rules, and incident response. - Provides deployable detection rules. The guide's fingerprints were turned into rules you can use directly. The host and log layer is covered by Sigma atomic and correlation rules (
detections/sigma/), and the network layer by Suricata rules (detections/suricata/) that target the enrich prober and norma SDK WebFetch User-Agents. - Visualized ATT&CK coverage. The techniques that the rules tag were organized into a MITRE ATT&CK Navigator layer (
detections/attack/). - Provides machine-readable indicators of compromise (IoCs) in standard formats. The unique fingerprints that ARTEX emits were collected into a single CSV (
detections/indicators/artex_indicators.csv), along with a MISP event (detections/indicators/artex_indicators.misp.json) carrying the same indicators that can be imported straight into a threat-intelligence platform. Indicators that a rule backs are marked withto_ids, while host-forensic ports are marked separately as triage clues. - Attached reproducible detection tests. Eight test suites prove the rules by actually running them (Sigma structure and compilation checks, Sigma live event-matching, backend portability, SigmaHQ convention lint, Suricata load and firing, ATT&CK layer consistency, indicator-to-source matching, and MISP export ↔ CSV synchronization). A batch runner that runs them all at once and a pre-commit example were added and wired into the CI merge gate. Sigma live event-matching confirms that the rules not only compile but actually fire on malicious sample events and stay silent on benign ones, for both the atomic and the correlation rules.
Repository hardening
- Added security and misuse warnings and Korean legal notices. The scope of use, notices under the Network Act and the Personal Information Protection Act, and a misuse-prohibition warning were added at the top of the README.
- Replaced the screen preview with Korean UI screenshots.
- Set up a maintainer runbook and a contributing guide. Added a runbook (
MAINTAINING.en.md) for preventing upstream-sync and translation drift, and a detection-rule contribution contract (CONTRIBUTING.en.md). The runbook also documents the release pipeline's build assumptions and how to verify them locally without a tag. - Added push/PR merge-gate CI. The upstream repository ran CI only on tag releases, but this fork runs — on every push and pull request — a Go build, static analysis (
go vet), and unit tests (ci.yml); a Korean UI static build (web.yml); and integrity checks for the documentation's repository-internal links and image references (docs.yml), catching regressions introduced during localization before they merge. Integration tests that require a database are verified alongside a PostgreSQL service isolated per package. The documentation link check runs as a deterministic script (scripts/check-doc-links.py) that does not depend on an external network, so the many relative links the multilingual documents point at one another — and the screen-preview images — cannot merge while broken. Documentation anchor (#heading) links are also checked against headings using the same slug rules as GitHub, catching table-of-contents and cross-reference links that silently break when heading text changes. The detection-rule suite is handled by the merge gate described in the "Defense and detection resources" section above. - Periodically checks external-link liveness. External links the documents point at — the defense guide's incident-reporting channels and standards references — depend on remote server state and are flaky, so they are kept out of the merge gate; instead a non-blocking workflow (
external-links) runs a browser-User-Agent, GET, redirect-following check (scripts/check-external-links.py) every Monday and on manual dispatch. A host that is alive but blocks the check method (bot protection, rate limiting) and upstream-inherited dead links we cannot fix (an allowlist) are not counted as failures, so it turns red only when an external link our documents curate newly breaks. - Established contribution and governance infrastructure. Added bug, feature, and translation issue templates (
.github/ISSUE_TEMPLATE/) and a pull-request template (PULL_REQUEST_TEMPLATE.md), a security-vulnerability reporting policy (SECURITY.en.md), and a code of conduct (CODE_OF_CONDUCT.en.md), so that external contributors submit issues, PRs, and security reports in a consistent format. - Completed an English documentation layer for overseas contributors. This repository is Korean-first, but English versions of the core documents are provided so that contributors, security researchers, and defenders who do not read Korean can reach the same information. In addition to the English
README.en.mdand the defense guide (docs/defense-en.md), there are English versions of the changelog (CHANGELOG.en.md), the security reporting policy (SECURITY.en.md), the code of conduct (CODE_OF_CONDUCT.en.md), the contributing guide (CONTRIBUTING.en.md), the maintainer runbook (MAINTAINING.en.md), the traffic-evidence design document (docs/finding-traffic-evidence-en.md), and the bug, feature, and translation issue templates. The Korean and English versions link to each other in their headers, so you can move to the other language from whichever one you arrive at. (The pull-request template is currently Korean-only.)
The upstream ARTEX project's per-version release history and contributor list can be viewed verbatim in CHANGELOG.zh.md.