PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 26, 20260 citationsOpen Access

Cryptographic Security Assessment of IBM z/OS Mainframe Infrastructure Using CASI Distributional Analysis

View Full Paper
DFDavid Tom Foss

Key Points

  • This research aims to assess the cryptographic security of IBM z/OS mainframe infrastructure, focusing on key vulnerabilities.
  • Utilized Compression-Adjusted Structural Integrity (CASI) for statistical analysis.
  • Conducted assessments on RACF password hashing and TN3270 protocol security.
  • Validated findings on IBM z15 hardware and the vendor's educational platform.
  • Performed all tests within authorized emulation and production environments.
  • Key entropy for RACF Legacy DES derivation reduced to 42.17 bits, allowing quick keyspace exhaustion.
  • Identified TN3270 operating without AT-TLS, exposing credentials in cleartext.
  • All 23 IBM MQ channels found to be unencrypted.
  • Discovered ICSF hardware cryptography lacking necessary RACF authorization checks.

Abstract

We present a comprehensive cryptographic security assessment of IBM z/OS mainframe infrastructure using the Compression-Adjusted Structural Integrity (CASI) metric—a black-box statistical method for detecting non-random structure in byte sequences (IEEE peer-reviewed, ICECET 2026). Our analysis spans 50 findings across RACF password hashing, TN3270 protocol security, AT-TLS enforcement, IBM MQ channel encryption, and ICSF cryptographic authorization. The core finding is that RACF Legacy DES key derivation reduces effective key entropy from 56 bits to 42. 17 bits through EBCDIC encoding dead zones, enabling complete keyspace exhaustion in 7. 6 minutes on consumer GPU hardware (0. 08 cloud cost). We validate this finding bit-for-bit on real IBM z15 hardware (z/OS V2. 5) via the vendor's educational z/OS platform, achieving 4/4 perfect matches between our model and the production RACF implementation. Beyond RACF, we discover that the vendor's educational z/OS infrastructure runs TN3270 without AT-TLS encryption (credentials in cleartext), operates IBM MQ V9. 4. 5 with all 23 channels unencrypted, and configures ICSF hardware cryptography without RACF authorization checks. A ghost AT-TLS policy from 2016 exists for an unused port but was never applied to the production TN3270 service. All testing was performed within authorized environments: Hercules 4. 9. 1 emulation with TK5 MVS 3. 8j for initial analysis, and the vendor's educational platform (real IBM z15) for production validation. External systems discovered in MQ channel configurations were not accessed. 97 configuration artifacts are available to the vendor upon request.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

David Tom Foss (2026) studied this question.

synapsesocial.com/papers/699fe32295ddcd3a253e6c58https://doi.org/10.5281/zenodo.18755825
Ask AI
Helpful
Bookmark
Share
View Full Paper