Workload recording and replication to facilitate security testing

By recording and copying computer workloads and using a workload analyzer for security testing, the challenge of automating security testing in complex systems is solved, thereby improving system security and stability.

CN122270760APending Publication Date: 2026-06-23INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INTERNATIONAL BUSINESS MACHINE CORPORATION
Filing Date
2024-10-29
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively test and ensure the security and stability of computer systems, especially in complex systems where security testing is difficult to automate and may affect the normal operation of the system.

Method used

By recording and copying computer workloads, workload analyzers can be used to access, store, and recreate workloads for security testing, including modifying environment variables to generate modified workloads for testing.

Benefits of technology

It enables security testing without affecting the normal operation of the system, improves the security and stability of the system, and provides an automated security testing method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122270760A_ABST
    Figure CN122270760A_ABST
Patent Text Reader

Abstract

The computing device accesses the current workload. The computing device saves the current workload in a computer workload accessible format that is used to replicate the current workload. Security testing can be performed using the computer workload accessible format.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates generally to computer security testing, and more specifically to the storage and reconstruction of workloads to facilitate security testing. Background Technology

[0002] Embodiments of this disclosure relate to computer security testing. As computing systems and software typically continue to become increasingly complex, a single error in a line of source code, a faulty parameter call, or other such error can cause an entire computer system to become unstable or crash. The extreme complexity of modern computing hardware and software makes testing these problems difficult or virtually impossible to achieve with any certainty. However, despite the complexity and difficulty, security testing remains an important part of the computer product lifecycle because computer products must be extremely reliable and stable to maximize their value to the public. Security, stability, and system integrity are all essential in computing environments, despite the complexity of modern computing.

[0003] Therefore, computer system security testing requires a simple, streamlined, and automated method. Summary of the Invention

[0004] This invention discloses a method, system, and computer program product. According to an embodiment of the invention, a computing device accesses and records the current workload. The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload.

[0005] In an alternative aspect of the invention, embodiments of the invention disclose another method, system, and computer program product for utilizing stored workloads in security testing. A computing device accesses and records the current workload. The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload. The computing device receives a request for security testing. The computing device accesses the computer workload-accessible format. The computing device loads the computer workload-accessible format into the computing environment to recreate the previous workload. The computing device performs security testing on the previous workload.

[0006] In another alternative aspect of the invention, embodiments disclose another method, system, and computer program product for utilizing a stored workload in security testing. A computing device accesses and records the current workload. The computing device accesses and records one or more environment variables associated with the current workload. The computing device saves the current workload and one or more environment variables in a computer workload-accessible format, which can be used to copy the current workload and one or more environment variables. The computing device receives a request for security testing. The computing device accesses the computer workload-accessible format. The computing device modifies one or more environment variables associated with the computer workload-accessible format to generate a modified workload. The computing device deploys the modified workload. The computer device performs security testing on the modified workload. Attached Figure Description

[0007] Figure 1 This refers to a networked computer environment 100 according to an embodiment of the present invention.

[0008] Figure 2 This is a functional block diagram illustrating a workload testing module 200 according to an embodiment of the present invention.

[0009] Figure 3 This is a flowchart 300 depicting the operational steps that can be performed by the hardware components of a hardware device according to an embodiment of the present invention.

[0010] Figure 4 This is a flowchart 400 depicting operational steps that can be performed by hardware components of a hardware device according to an alternative embodiment of the present invention.

[0011] Figure 5 This is a flowchart 500 depicting operational steps that can be performed by hardware components of a hardware device according to another alternative embodiment of the present invention. Detailed Implementation

[0012] The currently disclosed embodiments relate to one or more methods, systems, and computer program products for facilitating security testing in computing environments using real-world computer workloads. By automating or nearly automating workload testing of different computing systems, improved computer security, stability, and safety can be achieved rapidly. Testing of computer workloads can even occur outside the computing environment itself, allowing the computing environment to continue operating while testing is being performed, thus providing uninterrupted service. Various embodiments of the invention present different advantages, including the ability to access workloads in the computing environment, store workloads, and subsequently recreate workloads to facilitate testing, as well as other advantages disclosed herein. However, the currently disclosed embodiments can be implemented in different ways in various embodiments of the invention, including as a standalone application, as part of the computer system under test, or in any other way when within the scope of the invention disclosed herein.

[0013] Various aspects of this disclosure are described by narrative text, flowcharts, block diagrams of computer systems, and / or block diagrams of machine logic included in embodiments of a computer program product (CPP). Regarding any flowchart, depending on the technology involved, operations may be performed in a different order than that shown in a given flowchart. For example, again according to the technology involved, two operations shown in consecutive flowchart blocks may be performed in reverse order, as a single integrated step, simultaneously, or in a manner that at least partially overlaps in time.

[0014] Computer Program Product Embodiment (“CPP Embodiment” or “CPP”) is a term used in this disclosure to describe any collection of one or more storage media (also referred to as “media”) collectively included in a collection of one or more storage devices, the collection of one or more storage devices collectively including machine-readable code corresponding to instructions and / or data for performing computer operations specified in a given CPP claim. A “storage device” is any tangible device capable of holding and storing instructions used by a computer processor. Without limitation, a computer-readable storage medium can be an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these media include: magnetic disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), memory sticks, floppy disks, mechanical encoding devices (such as punch cards or pits / platforms formed in the main surface of the disk), or any suitable combination of the foregoing. Computer-readable storage media, as used in this disclosure, should not be construed as storing transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides, optical pulses through fiber optic cables, electrical signals transmitted through wires, and / or other transmission media. As those skilled in the art will understand, data is typically moved at certain incidental points in time during the normal operation of the storage device, such as during access, defragmentation, or garbage collection; however, this does not make the storage device transient, because the data is not transient when it is stored.

[0015] The computing environment 100 includes examples of environments for executing computer code at least partially related to implementing the methods of the present invention, such as code related to the workload testing module 200. In addition to module 200, the computing environment 100 includes, for example, a computer 101, a wide area network (WAN) 102, an end-user equipment (EUD) 103, a remote server 104, a public cloud 105, and a private cloud 106. In this embodiment, the computer 101 includes a processor set 110 (including processing circuitry 120 and a cache 121), a communication structure 111, volatile memory 112, persistent storage device 113 (including an operating system 122 and module 200, as described above), a peripheral device set 114 (including a user interface (UI) device set 123, a storage device 124, and an Internet of Things (IoT) sensor set 125), and a network module 115. The remote server 104 includes a remote database 130. Public cloud 105 includes gateway 140, cloud coordination module 141, host physical machine set 142, virtual machine set 143, and container set 144.

[0016] Computer 101 can take the form of a desktop computer, laptop computer, tablet computer, smartphone, smartwatch or other wearable computer, mainframe computer, quantum computer, or any other form of computer or mobile device now known or to be developed in the future capable of running programs, accessing networks, or querying databases such as remote database 130. As is well known in the field of computer technology, and depending on the technology, the performance of a computer-implemented method can be distributed across multiple computers and / or multiple locations. On the other hand, in this presentation of computing environment 100, the detailed discussion focuses on a single computer, specifically computer 101, to keep the presentation as simple as possible. Computer 101 can reside in the cloud, even... Figure 1 It is not shown in the cloud, and on the other hand, computer 101 does not need to be in the cloud unless it can be indicated with certainty to any extent.

[0017] Processor assembly 110 includes one or more computer processors of any type now known or to be developed in the future. In this document, processor assembly 110 may also be referred to as one or more “computing devices,” but a computing device may also refer to one or more CPUs, microchips, integrated circuits, embedded systems, or equivalents, whether existing or future. Processing circuitry 120 may be distributed across multiple packages, such as multiple cooperating integrated circuit chips. Processing circuitry 120 may implement multiple processor threads and / or multiple processor cores. Cache 121 is memory located within the processor chip package and is typically used for data or code that should be readily accessible by the threads or cores running on processor assembly 110. Cache memory is typically organized into multiple levels based on its relative proximity to the processing circuitry. Alternatively, some or all of the cache in the processor assembly may be located “off-chip.” In some computing environments, processor assembly 110 may be designed to work with qubits and perform quantum computing.

[0018] Computer-readable program instructions are typically loaded onto computer 101 to cause the processor set 110 of computer 101 to perform a series of operational steps to implement a computer-implemented method, such that the instructions thus executed instantiate the method specified in the flowcharts and / or descriptive descriptions of the computer-implemented method included in this document (collectively, the “method of the invention”). These computer-readable program instructions are stored in various types of computer-readable storage media, such as cache 121 and other storage media discussed below. The program instructions and associated data are accessed by the processor set 110 to control and direct the execution of the method of the invention. In computing environment 100, at least some of the instructions for performing the method of the invention may be stored in module 200 of permanent storage device 113.

[0019] Communication structure 111 is a signal transmission path that allows the various components of computer 101 to communicate with each other. Typically, this structure consists of switches and conductive paths, such as switches and conductive paths that form buses, bridges, physical input / output ports, etc. Other types of signal communication paths can be used, such as fiber optic communication paths and / or wireless communication paths.

[0020] Volatile memory 112 is any type of volatile memory now known or to be developed in the future. Examples include dynamic random access memory (RAM) or static RAM. Typically, volatile memory 112 is characterized by random access, but this is not necessary unless explicitly stated otherwise. In computer 101, volatile memory 112 is located in a single package and is internal to computer 101; however, alternatively or additionally, volatile memory may be distributed across multiple packages and / or located externally relative to computer 101.

[0021] The persistent storage device 113 is any form of non-volatile memory for a computer, now known or to be developed in the future. The non-volatility of this memory means that the stored data is retained regardless of whether the computer 101 and / or the persistent storage device 113 is powered. The persistent storage device 113 may be a read-only memory (ROM), but typically at least a portion of the persistent memory allows data to be written, deleted, and rewritten. Some common forms of persistent storage include hard disks and solid-state storage devices. The operating system 122 may take several forms, such as various known proprietary operating systems or operating systems employing an open-source portable operating system interface type with a kernel. The code included in module 200 typically includes at least some of the computer code involved in performing the methods of the present invention.

[0022] Peripheral device set 114 includes a set of peripheral devices for computer 101. Data communication connections between peripheral devices and other components of computer 101 can be implemented in various ways, such as Bluetooth connectivity, near field communication (NFC) connectivity, connections made by cables (such as Universal Serial Bus (USB) type cables), plug-in connections (e.g., secure digital (SD) cards), connections made through local area communication networks, and even connections made through wide area networks such as the Internet. In various embodiments, UI device set 123 may include components such as displays, speakers, microphones, wearable devices (such as goggles and smartwatches), keyboards, mice, printers, touchpads, game controllers, and haptic devices. Storage device 124 is an external storage device, such as an external hard drive, or a pluggable storage device, such as an SD card. Storage device 124 can be permanent and / or volatile. In some embodiments, storage device 124 may take the form of a quantum computing storage device for storing data in the form of qubits. In embodiments where computer 101 requires substantial storage (e.g., where computer 101 locally stores and manages a large database), this storage can be provided by peripheral storage devices designed for storing very large amounts of data, such as a Storage Area Network (SAN) shared by multiple geographically distributed computers. The IoT sensor set 125 comprises sensors that can be used in IoT applications. For example, one sensor could be a thermometer, while another could be a motion detector.

[0023] Network module 115 is a collection of computer software, hardware, and firmware that allows computer 101 to communicate with other computers via WAN 102. Network module 115 may include hardware such as a modem or Wi-Fi transceiver, software for packetizing and / or depacketizing data transmitted over the communication network, and / or web browser software for transmitting data over the Internet. In some embodiments, the network control and network forwarding functions of network module 115 are performed on the same physical hardware device. In other embodiments (e.g., embodiments utilizing Software-Defined Networking (SDN)), the control and forwarding functions of network module 115 are performed on physically separate devices, such that the control function manages several different network hardware devices. Computer-readable program instructions for performing the methods of the present invention can typically be downloaded to computer 101 from an external computer or external storage device via a network adapter card or network interface included in network module 115.

[0024] WAN 102 is any wide area network (e.g., the Internet) capable of transmitting computer data over non-local distances using any technology known now or developed in the future for transmitting computer data. In some embodiments, WAN 102 may be replaced by and / or supplemented by a local area network (LAN) designed to transmit data between devices located in a local area, such as a Wi-Fi network. WANs and / or LANs typically include computer hardware such as copper transmission cables, fiber optic transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and edge servers.

[0025] End User Equipment (EUD) 103 is any computer system used and controlled by an end user (e.g., a customer of the enterprise operating computer 101) and can take any of the forms discussed above in conjunction with computer 101. EUD 103 typically receives useful and available data from the operation of computer 101. For example, assuming computer 101 is designed to provide recommendations to an end user, these recommendations are typically transmitted from network module 115 of computer 101 to EUD 103 via WAN 102. In this way, EUD 103 can display or otherwise present recommendations to the end user. In some embodiments, EUD 103 can be client equipment such as a thin client, heavy client, mainframe, desktop computer, etc.

[0026] Remote server 104 is any computer system that provides at least some data and / or functionality to computer 101. Remote server 104 can be controlled and used by the same entity operating computer 101. Remote server 104 represents a machine that collects and stores useful and available data used by other computers, such as computer 101. For example, if computer 101 is designed and programmed to provide recommendations based on historical data, that historical data can be provided to computer 101 from a remote database 130 of remote server 104.

[0027] Public cloud 105 is any computer system that can be used by multiple entities, providing on-demand availability of computer system resources and / or other computing capabilities (particularly data storage (cloud storage) and computing power) without the need for direct, active management by users. Cloud computing typically leverages resource sharing to achieve scalability consistency and economy. Direct and active management of the computing resources of public cloud 105 is performed by the computer hardware and / or software of cloud coordination module 141. The computing resources provided by public cloud 105 are typically implemented by virtual computing environments running on various computers constituting the host physical machine set 142, which is the entirety of physical computers in and / or available to the public cloud 105. Virtual computing environments (VCEs) typically take the form of virtual machines from virtual machine set 143 and / or containers from container set 144. It should be understood that these VCEs can be stored as images and can be transferred between various physical machine hosts as images or after the VCEs are instantiated. Cloud coordination module 141 manages the transfer and storage of images, deploys new instantiations of VCEs, and manages the active instantiation of VCE deployments. Gateway 140 is a collection of computer software, hardware, and firmware that allow public cloud 105 to communicate via WAN 102.

[0028] Now, we will provide some further explanation of Virtualized Computing Environments (VCEs). A VCE can be stored as an "image." A new active instance of a VCE can be instantiated from this image. Two common types of VCEs are virtual machines and containers. A container is a VCE that uses operating system-level virtualization. This refers to an operating system feature where the kernel allows multiple isolated user-space instances, called containers, to exist. From the perspective of the programs running within them, these isolated user-space instances typically appear as actual computers. Computer programs running on a regular operating system can utilize all the resources of that computer, such as connected devices, files and folders, network shares, CPU power, and quantifiable hardware capabilities. However, programs running within a container can only use the contents of the container and the devices allocated to the container; this is a characteristic known as containerization.

[0029] Private cloud 106 is similar to public cloud 105, except that computing resources are available only to a single enterprise. While private cloud 106 is depicted as communicating with WAN 102, in other embodiments, private cloud may be completely disconnected from the Internet and accessible only via a local / private network. A hybrid cloud is a combination of multiple clouds of different types (e.g., private, community, or public cloud types) typically implemented by different vendors. Each of the multiple clouds remains a separate and discrete entity, but the larger hybrid cloud architecture is bound together by standardization or proprietary technology that enables coordination, management, and / or data / application portability across the multiple component clouds. In this embodiment, public cloud 105 and private cloud 106 are both part of a larger hybrid cloud.

[0030] Figure 2 This is a functional block diagram illustrating a workload testing module 200 according to an embodiment of the present invention. In embodiments of the present invention, such as… Figure 2 As shown, execution environment 210 is operatively connected to workload analyzer 260 directly or via network 299. In different embodiments of the invention, execution environment 210 can be any kind of computer hardware and associated software for executing any kind of computer software / function, such as bootloaders, login scripts, cloud server execution, large-scale transaction processing execution, enterprise resource planning, artificial intelligence software execution, etc. As those skilled in the art will understand, the computer software executed by execution environment 210 (of the different types discussed) may include various system calls, scripts, jobs, interface accesses, executable data, memory accesses, etc., and may require calls to other source code modules, executable files, computer hardware, etc., when performing different functions. Also as Figure 2 As shown, workload analyzer 260 represents any kind of computer hardware and associated software used for capturing, replaying, analyzing, modifying, error checking, security testing, and performing other functionalities discussed herein. In embodiments of the invention, workload analyzer 260 typically utilizes stored workloads to perform the security tests described herein (wherein the workloads are performed in execution environment 210).

[0031] like Figure 2 As shown in the various embodiments of the invention, execution environment 210 and workload analyzer 260 are connected to and via network 299. In various embodiments of the invention, network 299 represents, for example, any kind of computer network, such as a local area network (LAN), a wide area network (WAN), such as the Internet, and includes wired, wireless, or fiber optic connections. In various embodiments, network 299 is substantially as used herein. Figure 1The same applies to WAN102 discussed. Generally, according to embodiments of the invention, network 299 can be any combination of connections and protocols that support communication between execution environment 210 and workload analyzer 260. In further embodiments of the invention, network 299 can represent an internal bus associated with a single or multi-core processor of both execution environment 210 and workload analyzer 260 (such as in embodiments where execution environment 210 and workload analyzer 260 are integrated).

[0032] To discuss in more detail Figure 2 The elements shown, execution environment 210, represent computer hardware and / or software that executes a workload. Execution environment 210 may include one or more computer processors (including registers, caches, etc.), logic circuitry, computer memory, secondary storage, etc., and associated firmware, software, etc., that allow the execution of the "workload". Any kind of execution environment 210 is contemplated within the embodiments of the invention disclosed herein and utilizes various aspects of the invention. As discussed herein, a "workload" refers to any kind of execution of a computer program application, database access, logical operation, startup sequence, etc., or any other software executed in execution environment 210. As a non-limiting example, a workload executed by execution environment 210 may be a bootloader, login script, cloud server, large-scale transaction processing, enterprise resource planning, artificial intelligence software, etc. In embodiments of the invention, execution environment 210 may require security testing to ensure the existence of a stable computing environment for specialized capabilities. Certain regulations or legal requirements may even require security testing within certain applications. In other embodiments of the invention, workloads executed in execution environment 210 may be stored for other uses.

[0033] In various embodiments, as previously discussed, the execution environment 210 includes a computer workload 213.

[0034] In embodiments of the invention, the computer workload 213 is executed by execution environment 210 (as further discussed herein). By way of non-limiting example, the computer workload 213 may include a bootloader, login script, cloud server, performance for large-scale transaction processing, enterprise resource planning, execution of artificial intelligence software, or any other type of execution software (as further discussed herein). As will be understood by those skilled in the art, the software associated with the computer workload 213 may include uncompiled / compiled / interpreted source code, bytecode and / or other types of computer software, database access, etc. Environment variables set independently within the computer workload 213 and / or elsewhere within execution environment 210 may also be included in the computer workload 213. In embodiments of the invention, the computer workload 213 may also include one or more of input parameters, scripts, jobs, executable data, traces, logs and / or other items. Embodiments of the invention may present the advantage of storing all such information. Other elements may also be included alternatively or additionally. In different embodiments of the invention, computer workload 213 may refer to the “current workload” executed in execution environment 210, but as discussed further in conjunction with workload analyzer 260, it may also be considered a “previous workload” (as discussed further herein) when stored and recreated by workload analyzer 260, which can be utilized in different ways as discussed herein.

[0035] See also Figure 2 In various embodiments of the invention, workload analyzer 260 represents software and / or hardware for accessing, storing, recreating, and storing workloads executed within execution environment 210, as well as performing security tests on the workloads (and, in embodiments of the invention, performing other functions disclosed herein). As discussed, security testing is an essential aspect of the release of computer software and hardware. While the complexity of computer software and hardware continues to grow, the human capacity to understand and flawed test the vast amounts of modern software / hardware is limited. The currently disclosed embodiments present the advantage of automating important parts of security testing. In various embodiments of the invention, workload analyzer 260 includes one or more of the following: workload access and capture module 262, workload analyzer module 268, security testing module 271, reporting module 276, and workload replay module 278.

[0036] The workload access and capture module 262 represents the software and / or hardware used to access and record the current workload in execution environment 210. Upon request, and according to a schedule (or otherwise initiated), the workload access and capture module 262 accesses and records the current workload executing in execution environment 210. In embodiments of the invention, access to and recording of the current workload can be performed in various ways, such as via an authorized computer interface associated with execution environment 210 that monitors the code being accessed / executed, via monitoring execution assembly instructions executed in execution environment 210, or in another equivalent manner. In embodiments of the invention, the workload access and capture module 262 also accesses and records one or more environment variables associated with the computer workload and execution environment 210. Environment variables can affect all processes executing within execution environment 210 (not just the current workload). This knowledge is useful in security testing because it can have a significant impact on the software executing in execution environment 210. Following the access and storage described above, the workload access and capture module 262 saves the current workload and optionally one or more environment variables in a computer workload-accessible format that can be used to replicate the current workload (and, in different embodiments, one or more environment variables). The current workload-accessible format is maintained / saved / stored by the workload access and capture module 262 for future use. The computer workload-accessible format can be any kind of computer file, image, etc. (such as computer images, other software, bytecode, assembly instructions, etc.) that allows the workload to be recreated at a later time. As further discussed herein, the current image saved by the workload access and capture module 262 is useful for security testing. In embodiments of the invention, the computer workload-accessible format is saved in a commonly accessible format that can be used to recreate the workload in other computing devices (such as workload analyzer 260 or other computing devices not shown herein). In yet another embodiment of the invention, the computer workload-accessible format is associated with a mapping to a list of parameters stored by the computer-accessible workload. This presents the advantage of determining the utilization of different parameters when analyzing computer workloads.

[0037] The workload analyzer module 268 represents software and / or hardware for analyzing stored workloads accessed and recorded by the workload access and capture module 262. In embodiments of the invention, the workload analyzer module 268 analyzes workloads in various ways, with the analysis serving different purposes as discussed herein, but particularly in security testing. In embodiments of the invention, the workload analyzer module 268 identifies calls to authorized interfaces and the format of the different parameters used to call those authorized interfaces within the current workload. This presents an advantage in security testing, for example, knowing which interfaces are called in the workload and how they are called. When performing security testing, interface calls within the workload can be very useful for identifying potential sources of, for example, errors and other inconsistencies. In different embodiments of the invention, the described interface knowledge can also be used for general workload analysis. In another embodiment of the invention, the workload analyzer module 268 stores a list mapping of one or more parameter lists and parameters indicating one or more locations where parameters are called in the current workload. This presents an advantage in security testing, identifying potential locations in the current workload that may be associated with one or more errors and specifically what is causing those errors. It also provides general information about the current workload that can be used for general workload analysis. The workload analyzer module 268 can also identify one or more potential modifications to one or more parameter list mappings that alter the invocation of parameters within the parameter list mappings. These potential modifications can be used, for example, to facilitate security testing, thereby providing several advantages, whereby, for example, the one or more potential modifications are associated with possible solutions to address the mentioned security issues. Different modifications can be automatically tried until a solution to the potential security problem is found.

[0038] Security testing module 271 represents software and / or hardware for performing security tests on workloads accessed and captured by workload access and capture module 262. In embodiments of the invention, to initiate a security test, a request to initiate a test is received. The request to initiate a security test may be initiated by a developer specifically requesting the test, or the security test may be initiated automatically based on the release of new software on execution environment 210, or it may be initiated in any other way. Other arrangements or conditions are envisioned herein for automatically initiating security tests by security testing module 271. Once the security test begins, security testing module 271 accesses the computer workload accessible format from workload access and capture module 268. Security testing module 271 then loads the computer workload accessible format into a local or remote computing environment to recreate the previous workload associated with the computer workload accessible format. After loading the previous workload, security testing module 271 then performs security tests on it. As discussed herein, the execution of tests on the previous workload associated with the computer workload accessible format presents advantages. It allows for accurate security testing without disrupting the software currently running on execution environment 210 (such as, for example, executing thousands of financial transactions 24-7 on execution environment 210). It also allows for security testing in a sandboxed environment, where program failures are not permitted in execution environment 210, and presents other advantages.

[0039] In various embodiments of the invention, the security tests performed by the security testing module 271 on the previous workload are performed in different ways. In one embodiment, when performing security tests, the workload analyzer security testing module 271 modifies one or more parameters in the service calls within the previous workload to generate a modified previous workload, and performs security tests on the modified previous workload. This presents the advantages of sandboxed testing (while execution can continue on execution environment 210) and various different methods for improving system security. In yet another embodiment of the invention, the workload analyzer security testing module 271 modifies one or more parameters in the service calls within the previous workload to generate a modified previous workload, executes the modified workload to generate one or more errors, and then analyzes the errors. This provides the advantage of allowing the workload analyzer 260 to make different modifications to the previous workload to determine what types of errors might be possible, and thereby learn to correct the errors (thus providing improved security, stability, etc. in execution environment 210). In different embodiments of the invention, the errors can be runtime errors, compilation errors, memory access errors, etc. In another embodiment of the invention, after analyzing errors, the workload analyzer 260 combines parameters in a service call or times-separates parameters within a service call to limit the scope of one or more errors. This presents the general advantage of limiting errors in a workload (leading to, for example, improved system security) in the specific manner discussed, specifically by altering the service call or times-separating parameters within the service call. In another embodiment of the invention, after loading a computer workload accessibility format, the security testing module 271 modifies one or more environment variables within the computer workload accessibility format to generate a modified previous workload and performs security tests on the modified previous workload. This provides the advantages of testing different environment variables in the modified workload and determining whether the changes result in, for example, a more stable or less stable environment, as well as providing other advantages. After generating the modified previous workload (or in conjunction with other embodiments herein), the security testing module 271 can analyze one or more program checks resulting from the security tests. When the execution environment 210 and / or the workload analyzer 260 detect programming errors, the program checks occur in the context of the software being executed by the execution environment 210. Program checks can be associated with “abnormal termination” or abnormal endings in the software executing in execution environment 210 and / or workload analyzer 260. Analysis of program checks triggered by security testing can provide more detail about potential errors to be avoided. This highlights the advantages of more detailed information in security testing, particularly regarding potential errors that may arise or be corrected.

[0040] Reporting module 276 represents software and / or hardware for reporting one or more security vulnerabilities, errors, abnormal terminations, program checks, and / or other security issues detected by workload analyzer 260 in conjunction with the embodiments disclosed herein. To best utilize information from workload analyzer 260 regarding programs executing in execution environment 210, information about potential errors, abnormal terminations, program checks, and security issues can be reported to one or more users who can take remedial measures to resolve these issues. Reporting module 275 can provide such reports via computer interface, scheduled emails, etc., with the aim of providing useful information to various types of users, such as developers, project managers, etc.

[0041] The workload replay module 278 represents software and / or hardware for replaying stored workloads from the execution environment 210. In existing embodiments of the invention, the workload replay module 278 can access a computer workload accessible format stored by the workload access and capture module, and utilize the computer workload accessible format to load associated computer workloads, and replay the workloads, etc. (Security testing of the workloads is not required.) This provides developers, projects, managers, etc., with the ability to review workloads in greater depth, make custom edits, release different versions, etc.

[0042] Figure 3 This is a flowchart depicting operational steps that can be performed by hardware components, multiple hardware components, and / or hardware devices according to embodiments of the present invention. Figure 3 As shown, in step 310, workload analyzer 260 accesses and records the current workload executing in execution environment 210. In step 330, workload analyzer 260 saves the current workload in a computer-accessible format that can be used to copy the current workload. For example, combining... Figure 3 The presented embodiments offer the advantage of independently storing the current workload in a computer-accessible format, which can be used to recreate the current workload while it is in progress or at a later time. This presents various advantages: for example, if it is desired to reproduce a previous workload later because a particular build of the software is more stable than a later version, embodiments of the invention can be used to recreate the previous workload. Particular advantages are presented in workload security testing. By allowing security testing to be performed in an independent computer environment, various different types of security tests can be tried on the same workload, and it can be determined which technique provides the best results (which can be rolled out at a later time). The execution environment 210 can continue to operate normally while independently performing tests (or other functionalities) through a workload analyzer 260 that operates independently of the execution environment 210.

[0043] Figure 4 This is a flowchart depicting alternative operational steps that can be performed by hardware components, multiple hardware components, and / or hardware devices according to embodiments of the present invention. Figure 4 As shown, in step 410, workload analyzer 260 accesses and records the current workload being executed in execution environment 210. In step 430, workload analyzer 260 saves the current workload in a computer-accessible format, which can be used to replicate the current workload. In step 440, workload analyzer 260 receives a request for security testing. In step 450, workload analyzer 260 accesses the computer workload-accessible format. In step 460, workload analyzer 260 loads the computer workload-accessible format into the computing environment to recreate the previous workload. In step 470, workload analyzer 260 performs security tests on the previous workload. (The last sentence appears to be incomplete and possibly refers to a different context.) Figure 4 The illustrated embodiment demonstrates the advantage of providing a separate computing environment for testing current workloads executed in execution environment 210. This separate computing environment, used for security testing of the workloads, then executes in execution environment 210, providing sandbox security testing while allowing execution to take place within execution environment 210. This results in security advantages while allowing execution to proceed normally within execution environment 210. If changes are needed to improve the security of execution environment 210, these changes can then be made subsequently during planned downtime.

[0044] Figure 5 This is a flowchart depicting further alternative operational steps that can be performed by hardware components, multiple hardware components, and / or hardware devices according to embodiments of the present invention. Figure 5 As shown, in step 510, workload analyzer 260 accesses and records the current workload being executed in execution environment 210. At step 520, workload analyzer 260 accesses and records one or more environment variables associated with the current workload in execution environment 210. At step 530, workload analyzer 260 saves the current workload and one or more environment variables in a computer-accessible format that can be used to replicate the current workload and one or more environment variables. At step 540, workload analyzer 260 receives a request for security testing. At step 550, workload analyzer 260 accesses the computer workload-accessible format. At step 560, workload analyzer 260 modifies one or more modifiable environment variables associated with the computer workload-accessible format to generate a modified workload. At step 570, workload analyzer 260 deploys the modified workload. At step 580, workload analyzer 260 performs security testing on the modified workload. (e.g., combining...) Figure 5The illustrated embodiment demonstrates the advantage of providing an independent computing environment for modifying and testing workloads executed in execution environment 210. This provides for incremental changes to modifiable environment variables stored in a computer workload-accessible format, and for security testing of the resulting modified workloads. The execution of independent security tests on the modified workloads by workload analyzer 260 allows the user to determine, for example, which modifications to environment variables result in more stable and unstable environments.

[0045] Based on the foregoing, a method, system, and computer program product have been disclosed. However, various modifications and substitutions can be made without departing from the scope of the invention. Therefore, the invention has been disclosed by way of example rather than limitation.

[0046] Examples of the present invention include: (1) A method for utilizing stored workloads in security testing using a computing device, the method comprising: The current workload is accessed and recorded by the computing device; The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload. The computing device receives a request for security testing; The computing device can access the computer workload in an accessible format. The computing device loads the computer workload into the computing environment in an accessible format to recreate the previous workload; and The computing device performs a security test on the previous workload. (2) The method according to clause (1), wherein the workload selectively includes one or more of the following: one or more environment variables, executable binary code, user identifier, input parameters, scripts, jobs, executable data, traces, records, events, timing, inputs, and outputs. (3) A method for utilizing stored workloads in security testing using a computing device, the method comprising: The current workload is accessed and recorded by the computing device; The computing device accesses and records one or more environment variables associated with the current workload; The computing device saves the current workload and the one or more environment variables in a computer workload-accessible format, which can be used to copy the current workload and the one or more environment variables. The computing device receives a request for security testing; The computing device can access the computer workload in an accessible format. The computing device modifies one or more modifiable environment variables associated with the accessible format of the computer workload to generate a modified workload; The modified workload is deployed by the computing device; and The computing device performs a security test on the modified workload. (4) A computer program product that utilizes a stored workload in a security test, the computer program product comprising: One or more non-transitory computer-readable storage media and program instructions stored on the one or more non-transitory computer-readable storage media capable of executing a method, the method comprising: The current workload is accessed and recorded by the computing device; The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload. The computing device receives a request for security testing; The computing device can access the computer workload in an accessible format. The computing device loads the computer workload into the computing environment in an accessible format to recreate the previous workload; and The computing device performs a security test on the previous workload. (5) The computer program product described in clause (4) further includes: analyzing one or more program checks caused by security testing. (6) A computer system that utilizes a storage workload in security testing, the computer system comprising: One or more computer processors; One or more computer-readable storage media; Program instructions used to access and record the current workload; Program instructions for accessing and recording one or more environment variables associated with the current workload by the computing device; Program instructions for saving the current workload and the one or more environment variables in a computer workload-accessible format, the computer workload-accessible format being used to copy the current workload and the one or more environment variables; Program instructions used to receive requests for security testing; Program instructions for accessing the computer workload in an accessible format; Program instructions for modifying one or more modifiable environment variables associated with the accessible format of the computer workload to generate a modified workload. Program instructions for deploying the modified workload; and Program instructions for performing security tests on the modified workload by the computing device. (7) The computer system described in clause (6) further includes: program instructions for analyzing one or more program checks caused by security testing. (8) The computer system pursuant to Clause (6), wherein the workload selectively includes one or more of the following: one or more environment variables, executable binary code, user identifiers, input parameters, scripts, jobs, executable data, traces, records, events, timings, inputs, and outputs.

Claims

1. A method of using a computing device, the method comprising: The current workload is accessed and recorded by the computing device; as well as The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload.

2. The method according to claim 1, further comprising: Identify calls to authorized interfaces and the format of parameters used to call the authorized interfaces within the current workload.

3. The method according to claim 1 or claim 2, further comprising: The storage includes one or more parameter list mappings that indicate the location where a parameter is invoked in the current workload and the function of that parameter.

4. The method according to claim 3, further comprising: Identify one or more potential modifications to the one or more parameter list mappings that alter the invocation of parameters in the parameter list mappings.

5. The method according to any one of the preceding claims further comprises: The computing device receives a request for security testing; The computing device can access the computer workload in an accessible format. as well as The computing device loads the computer workload into the computing environment in an accessible format to recreate the previous workload.

6. The method according to claim 5, further comprising: The computing device performs a security test on the previous workload.

7. The method according to claim 5 or 6, further comprising: Modify one or more parameters in the service calls within the previous workload to generate a modified previous workload, and perform security tests on the modified previous workload.

8. The method according to any one of claims 5 to 7, further comprising: Modify one or more parameters in the service calls within the previous workload to generate a modified previous workload, execute the modified previous workload to generate one or more errors, and analyze the errors.

9. The method according to claim 8, further comprising: After analyzing the error, the parameters in the service call are combined, or the parameters in the service call are separated by time to limit the scope of the one or more errors.

10. The method according to any one of claims 5 to 9, wherein, The current workload includes one or more environment variables.

11. The method of claim 10, further comprising: Modify one or more environment variables within the computer workload access format to generate a modified previous workload, and perform security tests on the modified previous workload.

12. The method of claim 11, further comprising: Analyze one or more program checks triggered by security testing.

13. The method of claim 6, further comprising: The report identifies one or more security vulnerabilities through security testing.

14. The method according to claim 6 or claim 13, wherein, The workload may selectively include one or more of the following: one or more environment variables, executable binary code, user identifiers, input parameters, scripts, jobs, executable data, traces, logs, events, timers, inputs, and outputs.

15. The method according to any one of the preceding claims, wherein, The workload may selectively include one or more of the following: one or more environment variables, executable binary code, user identifiers, input parameters, scripts, jobs, executable data, traces, logs, events, timers, inputs, and outputs.

16. The method according to any one of the preceding claims, wherein, The computer workload accessibility format is saved as a commonly accessible format.

17. The method according to any one of the preceding claims further comprises: The computing device can access the computer workload in an accessible format. Modify one or more modified environment variables in the computer workload access format to generate a modified workload; The modified workload is deployed by the computing device; and Perform security tests on the modified workload.

18. The method according to any one of the preceding claims, wherein, The computer workload access format is associated with a mapping to a list of parameters stored by the computer-accessible workload.

19. The method of claim 17, further comprising: The computing device accesses and records one or more environment variables related to the current workload; The computing device saves the one or more environment variables in a computer workload-accessible format, which can be used to copy the one or more environment variables; and The computing device receives a request for security testing.

20. A computer program product comprising: One or more non-transient computer-readable storage media and program instructions stored on the one or more non-transient computer-readable storage media, the program instructions being capable of performing a method comprising: The current workload is accessed and recorded by the computing device; and The computing device saves the current workload in a computer workload-accessible format, which can be used to copy the current workload.

21. The computer program product according to claim 20, wherein, The method further includes: The computing device receives a request for security testing; The computing device can access the computer workload in an accessible format. The computing device loads the computer workload into the computing environment in an accessible format to recreate the previous workload; and The computing device performs a security test on the previous workload.

22. The computer program product according to claim 21, wherein, The method also includes analyzing one or more program checks triggered by security testing.

23. A computer system, comprising: One or more computer processors; as well as One or more computer-readable storage media, wherein the one or more computer-readable storage media store: Program instructions used to access and record the current workload; as well as Program instructions for saving the current workload in a computer workload-accessible format, which can be used to copy the current workload.

24. The computer system according to claim 23, wherein, The one or more computer-readable storage media store: Program instructions for accessing and recording one or more environment variables related to the current workload by a computing device; Program instructions for saving the one or more environment variables in a computer workload-accessible format, the computer workload-accessible format being used to copy the one or more environment variables; Program instructions used to receive requests for security testing; Program instructions used to access computer workloads in accessible formats; Program instructions for modifying one or more modified environment variables associated with the accessible format of the computer workload to generate the modified workload. Program instructions used to deploy the modified workload; as well as Program instructions used by computing devices to perform security tests on modified workloads.

25. The computer system according to claim 24, further comprising: Program instructions used to analyze one or more program checks triggered by security testing.

26. The computer system according to claim 24 or 25, wherein, The workload may selectively include one or more of the following: one or more environment variables, executable binary code, user identifiers, input parameters, scripts, jobs, executable data, traces, logs, events, timers, inputs, and outputs.