We present a comprehensive cryptographic security assessment of IBM z/OS mainframe infrastructure using the Compression-Adjusted Structural Integrity (CASI) metric—a black-box statistical method for detecting non-random structure in byte sequences (IEEE peer-reviewed, ICECET 2026). Our analysis spans 50 findings across RACF password hashing, TN3270 protocol security, AT-TLS enforcement, IBM MQ channel encryption, and ICSF cryptographic authorization. The core finding is that RACF Legacy DES key derivation reduces effective key entropy from 56 bits to 42. 17 bits through EBCDIC encoding dead zones, enabling complete keyspace exhaustion in 7. 6 minutes on consumer GPU hardware (0. 08 cloud cost). We validate this finding bit-for-bit on real IBM z15 hardware (z/OS V2. 5) via the vendor's educational z/OS platform, achieving 4/4 perfect matches between our model and the production RACF implementation. Beyond RACF, we discover that the vendor's educational z/OS infrastructure runs TN3270 without AT-TLS encryption (credentials in cleartext), operates IBM MQ V9. 4. 5 with all 23 channels unencrypted, and configures ICSF hardware cryptography without RACF authorization checks. A ghost AT-TLS policy from 2016 exists for an unused port but was never applied to the production TN3270 service. All testing was performed within authorized environments: Hercules 4. 9. 1 emulation with TK5 MVS 3. 8j for initial analysis, and the vendor's educational platform (real IBM z15) for production validation. External systems discovered in MQ channel configurations were not accessed. 97 configuration artifacts are available to the vendor upon request.
David Tom Foss (2026) studied this question.