January 2013

Conference Paper

Computing Legacy Software Behavior to Understand Functionality and Security Properties: An IBM/370 Demonstration

By:
Linger, Richard C; Pleszkoch, Mark G; Prowell, Stacy J; Sayre, Kirk D; Ankrum, Scott
Publication Date:
January 29, 2013
Conference Name:
CSIIR Workshop
Conference Location:
Oak Ridge, Tennessee, United States of America
Conference Sponsor:
ORNL CSIIR

Abstract

Organizations maintaining mainframe legacy software can benefit from code modernization and incorporation of security capabilities to address the current threat environment. Oak Ridge National Laboratory is developing the Hyperion system to compute the behavior of software as a means to gain understanding of software functionality and security properties. Computation of functionality is critical to revealing security attributes, which are in fact specialized functional behaviors of software. Oak Ridge is collaborating with MITRE Corporation to conduct a demonstration project to compute behavior of legacy IBM Assembly Language code for a federal agency. The ultimate goal is to understand functionality and security vulnerabilities as a basis for code modernization. This paper reports on the first phase, to define functional semantics for IBM Assembly instructions and conduct behavior computation experiments.


Related Researchers