IP Library › Granted Patent US 12,361,137
Granted Patent B2
US 12,361,137 · App. 18/193,018 · Granted Jul 15, 2025

Cyber security testing with automated system message processing for input and result determination

Inventors: Michael Page Kasper (Poughkeepsie, NY); Eric Rosenfeld (Pleasant Valley, NY); Bryan Childs (Poughkeepsie, NY); Diane Marie Stamboni (Poughkeepsie, NY); Joshua David Steen (Fishkill, NY)
Assignee: International Business Machines Corporation
G06F21/577G06F11/3688
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,137
App. No.
18/193,018
Granted
Jul 15, 2025
Kind
B2
Abstract

Cyber security testing with automated system message processing for input and result determination is disclosed, including issuing, by a test tool, a call to an authorized service; identifying, by the test tool, one or more system-level error messages generated after issuing the call; determining, by the test tool based on at least one first system-level error message, a missing input for the call to the authorized service; and reissuing, by the test tool, the call to the authorized service with the missing input.

Claims (41)

1. A method of cyber security testing with automated system message processing for input and result determination, the method comprising:

issuing, by a test tool, a first call to an authorized service;

identifying, by the test tool, one or more system-level error messages generated after the first call is issued;

determining, by the test tool based on at least a first system-level error message, a missing input for the first call to the authorized service; and

reissuing, by the test tool, the first call to the authorized service with the missing input.

2. The method of claim 1 , wherein the test tool is configured to test for cybersecurity vulnerability.

3. The method of claim 1 , wherein the authorized service is configured to access restricted resources not accessible by the test tool.

4. The method of claim 1 , wherein the test tool is initialized without awareness one or more required inputs for the first call.

5. The method of claim 1 , wherein the first system-level error message is parsed based on a recognized message identifier to determine the missing input.

6. The method of claim 1 , wherein the first system-level error message is generated by at least one of an operating system and a security system.

7. The method of claim 1 further comprising:

issuing, by the test tool, a second call to the authorized service;

identifying, by the test tool, one or more system-level error messages generated after the second call is issued; and

identifying, by the test tool based on at least one second system-level error message, a potential security vulnerability of the authorized service in relation to a test case.

8. The method of claim 7 , wherein the potential security vulnerability is identified based on a sequence of related system-level error messages.

9. The method of claim 7 , wherein the potential security vulnerability includes at least one of service availability and privilege escalation.

10. The method of claim 7 , wherein the second system-level error message is parsed based on a recognized message identifier, and wherein a timestamp parsed from the second system-level error message is correlated to the test case.

11. An apparatus for cyber security testing with automated system message processing for input and result determination, the apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed therein computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

issuing, by a test tool, a first call to an authorized service;

identifying, by the test tool, one or more system-level error messages generated after the first call is issued;

determining, by the test tool based on at least a first system-level error message, a missing input for the first call to the authorized service; and

reissuing, by the test tool, the first call to the authorized service with the missing input.

12. The apparatus of claim 11 , wherein the authorized service is configured to access restricted resources not accessible by the test tool.

13. The apparatus of claim 11 , wherein the test tool is initialized without awareness one or more required inputs for the first call.

14. The apparatus of claim 11 , wherein the first system-level error message is parsed based on a recognized message identifier to determine the missing input.

15. The apparatus of claim 11 , further comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

issuing, by the test tool, a second call to the authorized service;

identifying, by the test tool, one or more system-level error messages generated after the second call is issued; and

identifying, by the test tool based on at least one second system-level error message, a potential security vulnerability of the authorized service in relation to a test case.

16. A computer program product for cyber security testing with automated system message processing for input and result determination, the computer program product comprising a computer readable storage medium having stored thereon computer program instructions that, when executed, cause a computer to carry out the steps of:

issuing, by a test tool, a first call to an authorized service;

identifying, by the test tool, one or more system-level error messages generated after the first call is issued;

determining, by the test tool based on at least a first system-level error message, a missing input for the first call to the authorized service; and

reissuing, by the test tool, the first call to the authorized service with the missing input.

17. The computer program product of claim 16 , wherein the computer program product further comprises computer program instructions that, when executed, cause the computer to carry out the steps of:

issuing, by the test tool, a second call to the authorized service;

identifying, by the test tool, one or more system-level error messages generated after the second call is issued; and

identifying, by the test tool based on at least one second system-level error message, a potential security vulnerability of the authorized service in relation to a test case.

18. The computer program product of claim 17 , wherein the potential security vulnerability is identified based on a sequence of related system-level error messages.

19. The computer program product of claim 17 , wherein the potential security vulnerability includes at least one of service availability and privilege escalation.

20. The computer program product of claim 17 , wherein the second system-level error message is parsed based on a recognized message identifier, and wherein a timestamp parsed from the second system-level error message is correlated to the test case.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2023
From: KASPER, MICHAEL PAGE; ROSENFELD, ERIC; CHILDS, BRYAN; STAMBONI, DIANE MARIE; STEEN, JOSHUA DAVID
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 063168/0578 →
Continuity (1)
Related Publication 20240330476A1 · Oct 3, 2024
References Cited (27)
US 7444548B2 · Shane · 2008 [cited by applicant]
US 8332952B2 · Zhang et al. · 2012 [cited by applicant]
US 8918885B2 · McClure et al. · 2014 [cited by applicant]
US 9213843B2 · Naldurg et al. · 2015 [cited by applicant]
US 9436829B2 · Tripp et al. · 2016 [cited by applicant]
US 10319457B2 · Childs et al. · 2019 [cited by applicant]
US 10803166B1 · Terkowitz et al. · 2020 [cited by applicant]
US 10872157B2 · Fong · 2020 [cited by applicant]
US 10915640B2 · Kasper et al. · 2021 [cited by applicant]
US 10977379B1 · Williams et al. · 2021 [cited by applicant]
US 11010479B2 · Childs et al. · 2021 [cited by applicant]
US 11030063B1 · Shipilov · 2021 [cited by examiner]
US 11294804B2 · Hicks et al. · 2022 [cited by applicant]
US 11500763B1 · Petrescu et al. · 2022 [cited by applicant]
US 20080104576A1 · Kaksonen · 2008 [cited by applicant]
US 20110191854A1 · Giakouminakis et al. · 2011 [cited by applicant]
US 20220253532A1 · Bishop, III · 2022 [cited by examiner]
US 20220391312A1 · Sharma · 2022 [cited by examiner]
US 20230376602A1 · Kasper et al. · 2023 [cited by applicant]
CN 108804912A · 2018 [cited by applicant]
CN 110688659A · 2020 [cited by applicant]
CN 110442524B · 2021 [cited by applicant]
CN 113204496A · 2021 [cited by applicant]
EP 3709592B1 · 2022 [cited by applicant]
Kasper et al., Detecting Security Vulnerabilities Through Dynamic Testing With Canary Programs, International Business Machines Corporation (IBM), U.S. Appl. No. 18/344,811, filed Jun. 29, 2023, 30 pages. [cited by applicant]
Mell et al., The NIST Definition of Cloud Computing, Recommendations of the National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Appendix P, List of IBM Patents or Patent Applications to be Treated as Related, Aug. 21, 2024, 2 pages. [cited by applicant]