SHIFT GROUP

News

Corporate News

SHIFT DQS for Reverse Engineering Introduces New “SBOM Analysis & Risk Management” Feature

SHIFT DQS for Reverse Engineering Introduces New
“SBOM Analysis & Risk Management” Feature

Comprehensive and Automated Visualization of Vulnerabilities and Risks in System Components and Dependencies Based on International Guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), Enabling Continuous Software Supply Chain Risk Management

SHIFT Inc. (“SHIFT,” headquartered in Minato-ku, Tokyo, Japan; Masaru Tange, CEO and Representative Director),  a provider of business transformation services rooted in quality, today announced an update to “SHIFT DQS for Reverse Engineering”—a solution that leverages AI to visualize internal and external system specifications from source code, generate over 46 types of documents, and centralize management via a dashboard. This update introduces the new “SBOM Analysis & Risk Management” feature, available starting today.

This feature combines static analysis with Large Language Model (LLM) analysis to examine source code, providing highly accurate identification and visualization of open-source software (OSS) and complex dependencies that are easily overlooked by manual audits or single-method analysis. It supports data output compliant with the latest international guidance established by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), “2026 Minimum Elements for a Software Bill of Materials,” helping organizations generate reliable SBOMs.

Furthermore, by integrating with global databases to assess vulnerability and licensing risks, as well as conducting End-of-Life (EOL) tracking, the feature enables a multifaceted understanding of risks embedded within system components. Assessment results are delivered through outputs such as a “Vulnerability List” and a “Diagnostic Report” detailing overall evaluations and actionable remediation advice, allowing companies to implement software supply chain risk management tailored to their specific needs—from periodic risk evaluations to continuous operations.

– Service Information Page: https://contents.shiftinc.jp/dqs-resbom/

[Background of Service Launch]
With rapid advancements in AI technology, including frontier AI, the generation of exploit code and the discovery of vulnerabilities have accelerated significantly. Conversely, manually extracting unmanaged libraries and complex dependencies hidden deep within legacy systems to create an accurate Software Bill of Materials (SBOM) remains a major challenge. Point-in-time approaches, such as conventional vulnerability assessments alone, are increasingly struggling to keep pace with rapidly escalating security requirements and evolving domestic and international regulations, such as Europe’s EU Cyber Resilience Act (CRA).

Additionally, legacy systems that have supported corporate growth for years often feature complex architectures due to repeated functional expansions. When vulnerabilities are detected, organizations frequently default to localized, piecemeal responses—such as applying patches to individual components with a priority on maintaining stable operations. However, when the full scope of a system is clearly visualized, organizations can look beyond temporary patches and evaluate medium- to long-term optimal strategies, including full-scale system modernization. Effective corporate security now demands an operational framework capable of accurately and promptly assessing the latest system status, enabling executive-level decision-making to determine whether a localized patch or a fundamental overhaul is required based on concrete data.

SHIFT has addressed black-box systems by providing “SHIFT DQS for Reverse Engineering,” leveraging AI to illuminate system structures and visualize specifications across an accumulated track record of analyzing over 200 million lines of source code. Furthermore, within the secure development framework of “SHIFT DQS for Forward Engineering,” which offers high-quality AI-driven development, SHIFT has actively implemented continuous and automated SBOM operations and built deep operational expertise. In the cybersecurity domain, SHIFT actively assists enterprise risk-response capabilities through services such as the “EU Cyber Resilience Act Compliance Support Service” and “Frontier AI Vulnerability Immediate Response Support.”

By consolidating this technological capability and operational expertise, SHIFT has introduced the new “SBOM Analysis & Risk Management” feature to “SHIFT DQS for Reverse Engineering.” This establishes an environment where enterprises can continuously monitor not only existing system specifications but also risks embedded within components and dependencies in a timely manner—empowering optimal, data-driven decisions ranging from localized remediation to full modernization.

[Key Features of “SBOM Analysis & Risk Management” in SHIFT DQS for Reverse Engineering]
The “SBOM Analysis & Risk Management” feature in SHIFT DQS for Reverse Engineering visualizes software components, dependencies, and associated risks directly from existing system source code.

High-Precision SBOM Generation Combining Static and LLM Analysis
By combining static code analysis with LLM-driven analysis, the solution visualizes dependencies and hidden components with high accuracy, minimizing omissions typical of manual audits or single-method analysis. Based on this visualized component data, it supports data output complying with CISA’s latest guidance, “2026 Minimum Elements for a Software Bill of Materials,” facilitating the generation of highly reliable SBOMs.

Multifaceted Risk Detection via Latest Global Database Integration and EOL Tracking
Integrates with global vulnerability databases to rapidly fetch and evaluate known vulnerabilities (CVEs) and licensing risks. Additionally, it supports EOL (End-of-Life) tracking for libraries and software, identifying support termination risks to provide a comprehensive view of embedded system vulnerabilities.

Evaluation results are provided via actionable deliverables, including a “Vulnerability List” detailing high-priority risks, and a “Diagnostic Report” offering aggregated assessments alongside concrete remediation guidance.

Centralized Management of System Specifications and Risk Data with Automated Document Updates
System specification documentation generated by SHIFT DQS for Reverse Engineering and risk data generated by this new feature can be managed centrally on a single dashboard. It flexibly supports one-time assessments, periodic evaluations, or continuous monitoring, with options to integrate automated updates for related documentation as required.

– Service Information Page: https://contents.shiftinc.jp/dqs-resbom/
– Inquiries Regarding the Service: https://contents.shiftinc.jp/dqs-re-sbom/#form

[Expected Benefits]
Reduced Workload and Accelerated Vulnerability Response
Automates manual dependency research and vulnerability checks, significantly lowering security management workloads. By clearly visualizing the impact scope of risks and concrete remediation steps, operational teams can quickly reference data, make decisions, and apply patches efficiently.

Establishing Governance Tailored to Organizational Operational Styles
Organizations can flexibly select a risk management model suited to their budget and operational structure—ranging from one-off risk discoveries and periodic audits to continuous real-time monitoring. By integrating with SHIFT’s suite of security support services—such as the “EU Cyber Resilience Act Compliance Support Service” and “Frontier AI Vulnerability Immediate Response Support”—companies can smoothly establish highly effective governance aligned with domestic and international regulations regardless of their operational style.

– EU Cyber Resilience Act Compliance Support Service: https://www.shiftinc.jp/news/20241210_sbom/
– Frontier AI Vulnerability Immediate Response Support: https://contents.shiftinc.jp/vulnerability-handling/

Supporting Strategic Decision-Making at the Executive Level
By rendering system structures and risk distribution visible, companies gain the insight needed to evaluate broader modernization efforts alongside immediate patch management. In coordination with SHIFT’s “AI Modernization Service,” management can make informed, data-driven decisions on whether to apply localized fixes or pursue fundamental system modernization.

[About SHIFT’s “AI Modernization”]
SHIFT’s AI Modernization service combines “SHIFT DQS (Development Quality Standard)”—a proprietary framework driving high-quality software development—with AI technology. By supporting system visualization, strategy formulation, development, and operation/maintenance, it enhances the asset value of existing systems while improving productivity and value creation in new development.

SHIFT DQS for Reverse Engineering
Visualizes internal and external specifications from source code to generate up to 46 document types. The core AI technology underpinning this service was developed and validated in collaboration with Matsuo Institute, Inc.

SHIFT DQS for Strategy
Analyzes As-Is and To-Be states using visualized data to establish an optimal phased roadmap for system modernization.

SHIFT DQS for Forward Engineering
Utilizes AI and SHIFT DQS to deliver high-quality software development with greater efficiency and cost effectiveness.

SHIFT DQS for Maintenance Support
Leverages AI to automate and streamline system operations and maintenance. Builds next-generation SRE frameworks focused on standardization and automation, including automated document updates during system modifications.

– Dedicated Site: https://contents.shiftinc.jp/modernization/
– Inquiries regarding AI Modernization: https://contents.shiftinc.jp/modernization/#contact

PAGE TOP TOP PAGE