Invention Grant
- Patent Title: Cyber security testing for authorized services
-
Application No.: US16148092Application Date: 2018-10-01
-
Publication No.: US10915640B2Publication Date: 2021-02-09
- Inventor: Michael P. Kasper , Bryan Childs , Kin Choi , Karl D. Schmitz , Kathryn Voss
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Cantor Colburn LLP
- Agent Teddi Maranzano
- Main IPC: G06F21/57
- IPC: G06F21/57

Abstract:
A system includes a memory system and a processing system operably coupled to the memory system. The processing system is configured to perform operations including setting a target register to point to a first protected storage location of the memory system resulting in a protection exception upon access, calling an authorized service, and confirming that the authorized service uses the target register based on detecting the protection exception. The target register is adjusted to point to a parameter list including one or more known values and a pointer to a second protected storage location resulting in the protection exception upon access to confirm use of a value of the parameter list responsive to calling the authorized service. Parameter list testing and target register testing is repeated for locations in the parameter list and target registers to construct a testing profile for vulnerability testing of the authorized service.
Information query