Close

Six Degrees of SPECIAL: Attack Path Modelling for RACF

(OM)

Stream: Melbourne
Time: 11:15 - 12:00


Presentation

Every RACF database tells the story of the system it protects. Access accumulates over years of migrations, mergers, emergency fixes, and requests that were entirely reasonable at the time: a group connection added for a project, an authority granted to resolve an incident at 3 a.m., or a profile copied because it was easier than determining exactly what was required. Each decision may have been sound in isolation, but the cumulative result is often an authorization structure that no one designed and no one can fully see. Individually legitimate permissions can combine to create unintended paths to privilege. These paths are difficult to identify through profile-by-profile review because the risk does not exist in any single profile; it exists in the relationships between users, groups, resources, datasets, and authorities. Graph databases are designed to analyse exactly these kinds of relationships. In the distributed world, BloodHound is widely used to identify privilege-escalation paths in Active Directory by modelling identities and permissions as a graph. Through its OpenGraph framework, the same approach can be applied to other authorization systems, including RACF. This talk introduces RACFHound, an open-source tool that transforms RACF unload data into a graph of users, groups, datasets, general resources, and system authorities. Once ingested into BloodHound, questions such as “Who can reach SPECIAL, and by what route?” no longer require a manual investigation across numerous profiles and group relationships. They become graph queries whose results can be explored as a visual, step-by-step path from an ordinary user to privileged control. No previous experience with graph theory or BloodHound is required. The session includes a short introduction to graph-based authorization analysis, followed by a practical demonstration of how RACFHound can uncover hidden privilege paths, explain why they exist, and help security teams prioritise remediation before those paths can be exploited.

Attachments

There is currently no attachment for Six Degrees of SPECIAL: Attack Path Modelling for RACF

Speakers


  • Jonathan Prince at NVISO GmbH
  • Jonathan spends his time breaking the systems enterprises trust most but understand least. Specializing in IBM z/OS and IBM i security, he researches privilege escalation, authorization flaws, and attack paths on platforms the industry forgot to threat-model. He runs a home lab with two AS/400s and enterprise gear to test these ideas in practice. His work applies modern offensive security methods to legacy platforms, showing how the path from a compromised account to mainframe domination may be far shorter than most defenders want to believe.


    Email: jonathan.prince@nviso.eu

    Feedback

    Click here to give some Feedback so we can make it even better next year!