Skip to content
Conference Open access

Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy it Security Concepts

Jul 2026 · International Conference on Computer, Information and Telecommunication Systems · pp. 1-8 · 0 citations · 23 references
Computer Science

TL;DR

The evaluation shows that ASSERT makes document-infrastructure inconsistencies measurable, but reveals a trade-off between discovering undocumented entities and enforcing a schema.

Abstract

The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts. The Open Security Controls Assessment Language (OSCAL) is a standard for this purpose, which the German Federal Office for Information Security (BSI) is adapting with Grundschutz++. However, companies are still managing extensive legacy IT security concepts (IT-SCs), and migrating them without verification could transfer outdated assets into the new format. While existing research primarily addresses the generation of new concepts, there is a lack of a verification framework that extracts legacy IT-SCs into an auditable intermediate representation, deterministically compares the extracted graph with an independently constructed reference state, and exports schemavalid OSCAL artifacts. This paper introduces the Automated Security Concept Structure Extraction and Reverse Topologychecking (ASSERT) Framework, which addresses this gap by using ontology-based extraction of legacy documents into formal document graphs, a five-class graph difference against a verified reference graph, and the export into schema-valid OSCAL outputs for system description and assessment evidence. Using the BSI's RecPlast dataset, we compare a local open-weight model and a commercial model across three configurations with different levels of reference-ontology exposure. The evaluation shows that ASSERT makes document-infrastructure inconsistencies measurable, but reveals a trade-off between discovering undocumented entities and enforcing a schema.

Read PDF

Similar papers

A Hybrid LLM-Based Framework for Automated Security Annotation Generation in Business Process Models

A hybrid framework that takes a BPMN process model and a security requirements document as input and automatically generates security annotations adhering to the SecBPMN2 specification is presented, providing a scalable foundation for security-by-design BPM.

Md Kamrul Islam, Tiphaine Henry, Mattia Salnitri et al. · 0 citations
Review Aug 2026

TopoIntent: Compiling Security Intent into Executable, Compliance-Checked Network Topologies

TopoIntent is presented, a system that compiles security intent into executable, compliance-checked network topologies, using a schema contract to constrain generation, retrieves reference architectures from a curated template library via dense-vector search, and applies staged fusion for intent-template alignment and...

Xiaokang Qu, Jian-Liang Ma, Z. Fan et al. · 0 citations
Conference Aug 2026

Research on a Rule-Driven Diagnosis and Automatic Refactoring Framework for IEC 61131-3 XML Control Programs

To address common quality problems in petroleum industrial control programs during function block reuse and engineering implementation, such as non-standard naming, missing comments, hard-coded numeric literals, and hidden cross-module dependencies, this paper proposes a rule-driven static diagnosis and structured refa...

Yifei Li, Hongye Zhao, Yu Song · 0 citations
Conference Aug 2026

MCSafe-GSN-HOL: A Formal Assurance Framework for Machine-Checkable Safety Cases of Deployed LLM Agents

Deployed large language model (LLM) agents are now being used to interface with external tools, fetch information, run code, interact with user data and help with decision making at the workflow level. Therefore, their safety issues are not only related to the underlying model, but also to tool permissions, prompt desi...

Aakash Abhay Yadav, Shashank Shelat, B. Hinduja et al. · 0 citations
Review Jul 2026

Validating ETCS Data with the B Mathematical Language: An Industrial Pipeline and a Blueprint for LLM Integration

The paper argues, on the evidence gathered so far, that formal rules in the mathematical language of B must remain the source of truth, while the language model serves as the fenced assistant in a distributed safety-critical railway system.

Thierry Lecomte, Vincent Germain · 0 citations
Review Open access Aug 2026

Integrating large language models and knowledge graphs for adaptive design review

This paper presents a framework integrating Knowledge Graphs and Large Language Models to support a more extensible design review environment, and demonstrates its ability to retrieve and execute existing rules from the KG, capture new requests during design, and maintain a verifiable, adaptive compliance checking syst...

Maen Alnuzha, Tanya Bloch · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.