LLM-Driven Compliance Copilot for FAPI 2.0 and SRC Specifications
Keywords:
FAPI 2.0, Secure Remote Commerce, OpenAPI, Terraform, proofs-of-possession, DevSecOpsAbstract
The objective of this article is to introduce a Large Language Model (LLM)-based compliance copilot for FAPI 2.0 and Secure Remote Commerce (SRC) standards. The proposed system fine-tunes a domain-specific LLM on OpenAPI standards and Terraform IaC stacks to automatically create red-line diffs and compliance artifacts that meet security, identity, and transaction assurance criteria.
Downloads
References
OpenID Foundation, “Financial-grade API (FAPI) Part 2: Read and Write API Security Profile,” OpenID Foundation, Tech. Rep., Feb. 2018.
EMVCo, “EMV 3-D Secure Protocol and Core Functions Specification,” EMVCo, Version 2.1.0, Sep. 2017.
PCI Security Standards Council, “PCI DSS: Payment Card Industry Data Security Standard,” Version 3.2, Apr. 2018.
L. Chen et al., “OpenAPI Specification: A Standard for RESTful API Descriptions,” IEEE Software, vol. 34, no. 3, pp. 96–99, May/Jun. 2017.
H. Wang et al., “Terraform: Infrastructure as Code for Cloud Provisioning,” in Proc. IEEE International Conference on Cloud Engineering, 2017, pp. 119–125.
D. Bahdanau, K. Cho, and Y. Bengio, “Neural Machine Translation by Jointly Learning to Align and Translate,” in Proc. International Conference on Learning Representations, 2015.
T. Brown et al., “Language Models are Few-Shot Learners,” arXiv preprint arXiv:2005.14165, 2020.
A. Vaswani et al., “Attention Is All You Need,” in Proc. 31st Conference on Neural Information Processing Systems (NIPS), 2017, pp. 6000–6010.
R. S. Sutton and A. G. Barto, Reinforcement Learning: An Introduction, 2nd ed., Cambridge, MA: MIT Press, 2018.
M. Fowler, Continuous Integration: Improving Software Quality and Reducing Risk, Boston, MA: Addison-Wesley, 2006.
OWASP, “OWASP Top Ten: The Ten Most Critical Web Application Security Risks,” The Open Web Application Security Project, 2017.
F. Chollet, Deep Learning with Python, Shelter Island, NY: Manning Publications, 2017.
NIST, “Framework for Improving Critical Infrastructure Cybersecurity,” National Institute of Standards and Technology, Version 1.1, Apr. 2018.
T. M. Mitchell, Machine Learning, New York, NY: McGraw-Hill, 1997.
J. H. Saltzer and M. D. Schroeder, “The Protection of Information in Computer Systems,” Proc. IEEE, vol. 63, no. 9, pp. 1278–1308, Sep. 1975.
J. M. Wing, “Computational Thinking,” Communications of the ACM, vol. 49, no. 3, pp. 33–35, Mar. 2006.
J. An and S. Cho, “Variational Autoencoder Based Anomaly Detection Using Reconstruction Probability,” Special Lecture on IE, vol. 2, no. 1, pp. 1–18, 2015.
G. Klein et al., “Using Formal Methods to Validate Security Properties of Protocols,” IEEE Security & Privacy, vol. 2, no. 2, pp. 32–39, Mar./Apr. 2004.
B. Schneier, Applied Cryptography: Protocols, Algorithms, and Source Code in C, 2nd ed., New York, NY: Wiley, 1996.
R. Sandhu et al., “Role-Based Access Control Models,” Computer, vol. 29, no. 2, pp. 38–47, Feb. 1996.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.