
리눅스 커널의 보안 강화 옵션을 확인하는 도구
(이전 명칭: kconfig-hardened-check)
Linux 커널에는 다양한 보안 강화 옵션이 있습니다. 대부분의 주요 배포판에서는 이러한 옵션을 기본적으로 활성화하지 않습니다. 시스템을 더 안전하게 만들기 위해 직접 이러한 옵션을 활성화해야 합니다.
하지만 설정을 수동으로 확인하는 것을 좋아하는 사람은 없습니다. 그러니 컴퓨터가 그 일을 하게 합시다!
kernel-hardening-checker (이전 명칭 kconfig-hardened-check)는 Linux 커널의 보안 강화 옵션을 확인하는 도구입니다.
라이선스: GPL-3.0.
kernel-hardening-checker는 다음을 확인할 수 있습니다:
지원 아키텍처:
보안 강화 권장 사항은 다음을 기반으로 합니다:
또한 [Linux 커널 방어 맵][4]을 만들었습니다. 이는 보안 강화 기능과 해당 취약점 클래스 또는 익스플로잇 기술 간의 관계를 그래픽으로 표현한 것입니다.
Linux 커널 보안 매개변수를 변경하면 시스템 성능과 사용자 공간 소프트웨어의 기능에 영향을 줄 수 있습니다. 따라서 이러한 매개변수를 설정할 때는 Linux 기반 정보 시스템의 위협 모델을 고려하고 일반적인 워크로드를 철저히 테스트하십시오.
여러 가지 옵션이 있습니다:
pip을 사용하여 이 Git 저장소에서 패키지를 설치할 수 있습니다:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
외부 관리 환경으로 인해 오류가 발생하면 python3 -m venv를 사용하여 가상 환경을 만드십시오.
일부 GNU/Linux 배포판의 패키지 관리자를 통해 kernel-hardening-checker 패키지를 설치할 수 있습니다. https://repology.org/project/kernel-hardening-checker/versions 참조
또는 클론된 저장소에서 설치 없이 ./bin/kernel-hardening-checker를 실행할 수 있습니다.
$ ./bin/kernel-hardening-checker -h usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}] [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE] [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}] [-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options: -h, --help show this help message and exit --version show program's version number and exit -m, --mode {verbose,json,show_ok,show_fail} select a special output mode instead of the default one -a, --autodetect autodetect and check the security hardening options of the running kernel -c, --config CONFIG check the security hardening options in a Kconfig file (also supports *.gz files) -v, --kernel-version KERNEL_VERSION extract the kernel version from a version file (such as /proc/version) instead of using a Kconfig file -l, --cmdline CMDLINE check the security hardening options in a kernel command line file (such as /proc/cmdline) -s, --sysctl SYSCTL check the security hardening options in a sysctl output file (the result of "sudo sysctl -a > file") -p, --print {X86_64,X86_32,ARM64,ARM,RISCV} print security hardening recommendations for the selected architecture -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV} generate a Kconfig fragment containing the security hardening options for the selected architecture
## 출력 모드
- 기본 출력 모드를 위한 `-m` 인수 없음 (아래 예시 참고)
- `-m verbose` 추가 정보 출력:
- 해당 검사가 없는 구성 옵션들
- AND/OR을 사용하는 복잡한 검사의 내부 구조, 예시:
```
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
```
- `-m json` 결과를 JSON 형식으로 출력 (`kernel-hardening-checker`를 다른 도구와 결합하기 위해)
- `-m show_ok` 성공한 검사만 표시
- `-m show_fail` 실패한 검사만 표시
## 출력 예시```
$ ./bin/kernel-hardening-checker -a
[+] Going to autodetect and check the security hardening options of the running kernel
[+] Detected version of the running kernel: (6, 11, 0)
[+] Detected kconfig file of the running kernel: /boot/config-6.11.0-1007-oem
[+] Detected cmdline parameters of the running kernel: /proc/cmdline
[+] Saved sysctls to a temporary file /tmp/sysctl-at_0n9si
[+] Detected architecture: X86_64
[+] Detected compiler: GCC 130200
[!] WARNING: sysctl options available for root are not found in /tmp/sysctl-at_0n9si, try checking the output of "sudo sysctl -a"
=========================================================================================================================
option_name | type | reason | decision |desired_val | check_result
=========================================================================================================================
CONFIG_BUG |kconfig| self_protection |defconfig | y | OK
CONFIG_SLUB_DEBUG |kconfig| self_protection |defconfig | y | OK
CONFIG_THREAD_INFO_IN_TASK |kconfig| self_protection |defconfig | y | OK
CONFIG_IOMMU_DEFAULT_PASSTHROUGH |kconfig| self_protection |defconfig | is not set | OK
CONFIG_IOMMU_SUPPORT |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR_STRONG |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_KERNEL_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_MODULE_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_REFCOUNT_FULL |kconfig| self_protection |defconfig | y | OK: version >= (5, 4, 208)
CONFIG_INIT_STACK_ALL_ZERO |kconfig| self_protection |defconfig | y | OK
CONFIG_CPU_MITIGATIONS |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOMIZE_BASE |kconfig| self_protection |defconfig | y | OK
CONFIG_VMAP_STACK |kconfig| self_protection |defconfig | y | OK
CONFIG_LSM_MMAP_MIN_ADDR |kconfig| self_protection |defconfig | 65536 | FAIL: "0"
CONFIG_DEBUG_WX |kconfig| self_protection |defconfig | y | OK
CONFIG_WERROR |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_X86_MCE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_V1 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SPECTRE_V2 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SSB |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MICROCODE |kconfig| self_protection |defconfig | y | OK
CONFIG_MICROCODE_INTEL |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_MICROCODE_AMD |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_X86_SMAP |kconfig| self_protection |defconfig | y | OK: version >= (5, 19, 0)
CONFIG_X86_UMIP |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_INTEL |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_AMD |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_RETPOLINE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_GDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RFDS |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_BHI |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_MDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TAA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_MMIO_STALE_DATA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_L1TF |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RETBLEED |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SRBDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TSA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_VMSCAPE |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_RANDOMIZE_MEMORY |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_KERNEL_IBT |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_MITIGATION_RETHUNK |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_PAGE_TABLE_ISOLATION|kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_UNRET_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_CALL_DEPTH_TRACKING |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBPB_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBRS_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SRSO |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_ITS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_INTEL_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_AMD_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOM_KMALLOC_CACHES |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_MERGE_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: "y"
CONFIG_BUG_ON_DATA_CORRUPTION |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SLAB_FREELIST_HARDENED |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_FREELIST_RANDOM |kconfig| self_protection | kspp | y | OK
CONFIG_SHUFFLE_PAGE_ALLOCATOR |kconfig| self_protection | kspp | y | OK
CONFIG_FORTIFY_SOURCE |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_VIRTUAL |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_ALLOC_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_STATIC_USERMODEHELPER |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SECURITY_LOCKDOWN_LSM |kconfig| self_protection | kspp | y | OK
CONFIG_LSM |kconfig| self_protection | kspp | *lockdown* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LOCKDOWN_LSM_EARLY |kconfig| self_protection | kspp | y | OK
CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY|kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_DEBUG_SG |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_ZERO_CALL_USED_REGS |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_CREDENTIALS |kconfig| self_protection | kspp | y | OK: version >= (6, 6, 8)
CONFIG_DEBUG_NOTIFIERS |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_KFENCE |kconfig| self_protection | kspp | y | OK
CONFIG_KFENCE_SAMPLE_INTERVAL |kconfig| self_protection | kspp | 100 | FAIL: "0"
CONFIG_RANDSTRUCT_FULL |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY |kconfig| self_protection | kspp | y | OK
CONFIG_HARDENED_USERCOPY_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY_FALLBACK |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_HARDENED_USERCOPY_PAGESPAN |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_GCC_PLUGIN_LATENT_ENTROPY |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_MODULE_SIG |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_ALL |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_SHA512 |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_FORCE |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_FREE_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_EFI_DISABLE_PCI_DMA |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RESET_ATTACK_MITIGATION |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_BOUNDS |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_LOCAL_BOUNDS |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_UBSAN_TRAP |kconfig| self_protection | kspp | y | FAIL: CONFIG_UBSAN_ENUM is not "is not set"
CONFIG_UBSAN_SANITIZE_ALL |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_SCHED_STACK_END_CHECK |kconfig| self_protection | kspp | y | OK
CONFIG_KSTACK_ERASE |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_KSTACK_ERASE_METRICS |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_KSTACK_ERASE_RUNTIME_DISABLE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_SCHED_CORE |kconfig| self_protection | kspp | y | OK
CONFIG_LIST_HARDENED |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT|kconfig| self_protection | kspp | y | OK
CONFIG_PAGE_TABLE_CHECK |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_PAGE_TABLE_CHECK_ENFORCED |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_DEFAULT_MMAP_MIN_ADDR |kconfig| self_protection | kspp | 65536 | OK
CONFIG_HW_RANDOM_TPM |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_CLANG |kconfig| self_protection | kspp | y | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_CFI_PERMISSIVE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_IOMMU_DEFAULT_DMA_STRICT |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INTEL_IOMMU_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_AUTO_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CFI_AUTO_DEFAULT is not present
CONFIG_MITIGATION_SLS |kconfig| self_protection | kspp | y | OK
CONFIG_INTEL_IOMMU_SVM |kconfig| self_protection | kspp | y | OK
CONFIG_AMD_IOMMU_V2 |kconfig| self_protection | kspp | y | OK: version >= (6, 7, 0)
CONFIG_SECURITY |kconfig| security_policy |defconfig | y | OK
CONFIG_SECURITY_YAMA |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *yama* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LANDLOCK |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *landlock* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_SELINUX_DISABLE |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_BOOTPARAM |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_SELINUX_DEVELOP |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_WRITABLE_HOOKS |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_DEBUG |kconfig| security_policy | kspp | is not set | OK
CONFIG_SECURITY_SELINUX |kconfig| security_policy |a13xp0p0v | y | OK
CONFIG_LSM |kconfig| security_policy |a13xp0p0v | *selinux* | OK: "apparmor" is in CONFIG_LSM
CONFIG_SECCOMP |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECCOMP_FILTER |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_BPF_UNPRIV_DEFAULT_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_X86_INTEL_TSX_MODE_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECURITY_DMESG_RESTRICT |kconfig|cut_attack_surface| kspp | y | OK
CONFIG_ACPI_CUSTOM_METHOD |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_COMPAT_BRK |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DEVKMEM |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_BINFMT_MISC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_INET_DIAG |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_KEXEC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_PROC_KCORE |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_LEGACY_PTYS |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_HIBERNATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IA32_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_X32 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_X32_ABI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODIFY_LDT_SYSCALL |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_OABI_COMPAT |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_MSR |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_LEGACY_TIOCSTI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODULE_FORCE_LOAD |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_M486 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_MODULES |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IO_STRICT_DEVMEM |kconfig|cut_attack_surface| kspp | y | FAIL: "is not set"
CONFIG_LDISC_AUTOLOAD |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_VSYSCALL_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT_VDSO |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DRM_LEGACY |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_FB |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_VT |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_BLK_DEV_FD |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_BLK_DEV_FD_RAWCMD |kconfig|cut_attack_surface|maintainer| is not set | OK
CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_N_GSM |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_ZSMALLOC_STAT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DEBUG_KMEMLEAK |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BINFMT_AOUT |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_KPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_UPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_GENERIC_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_FUNCTION_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_STACK_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HIST_TRIGGERS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_IO_TRACE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_VMCORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_PAGE_MONITOR |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USELIB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_CHECKPOINT_RESTORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USERFAULTFD |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HWPOISON_INJECT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MEM_SOFT_DIRTY |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEVPORT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEBUG_FS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_NOTIFIER_ERROR_INJECTION |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_FAIL_FUTEX |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PUNIT_ATOM_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_ACPI_CONFIGFS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_EDAC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DRM_I915_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DVB_C8SECTPFE |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MTD_SLRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MTD_PHRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IO_URING |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCMP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_RSEQ |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_LATENCYTOP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCOV |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_PROVIDE_OHCI1394_DMA_INIT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_SUNRPC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_X86_16BIT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_UBLK |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_SMB_SERVER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_XFS_ONLINE_SCRUB_STATS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_CACHESTAT_SYSCALL |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PREEMPTIRQ_TRACEPOINTS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_ENABLE_DEFAULT_TRACERS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PROVE_LOCKING |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_TEST_DEBUG_VIRTUAL |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MPTCP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_TLS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_TIPC |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IP_SCTP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_KGDB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PTDUMP_DEBUGFS |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_X86_PTDUMP |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_DEBUG_CLOSURES |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BCACHE_CLOSURES_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_STAGING |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KSM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KALLSYMS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KEXEC_FILE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_CRASH_DUMP |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_USER_NS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_X86_CPUID |kconfig|cut_attack_surface| clipos | is not set | FAIL: "m"
CONFIG_X86_IOPL_IOPERM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_ACPI_TABLE_UPGRADE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_EFI_CUSTOM_SSDT_OVERLAYS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_AIO |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ_SERIAL |kconfig|cut_attack_surface|grapheneos| is not set | FAIL: "y"
CONFIG_EFI_TEST |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "m"
CONFIG_MMIOTRACE_TEST |kconfig|cut_attack_surface| lockdown | is not set | OK
CONFIG_KPROBES |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_BPF_SYSCALL |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_MMIOTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_LIVEPATCH |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_IP_DCCP |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_FTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_VIDEO_VIVID |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_INPUT_EVBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_CORESIGHT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_XFS_SUPPORT_V4 |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_BLK_DEV_WRITE_MOUNTED |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_FAULT_INJECTION |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_ARM_PTDUMP_DEBUGFS |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_ARM_PTDUMP |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_SECCOMP_CACHE_DEBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_CRASH_DM_CRYPT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_LKDTM |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_TRIM_UNUSED_KSYMS |kconfig|cut_attack_surface|a13xp0p0v | y | FAIL: "is not set"
CONFIG_SYN_COOKIES |kconfig| network_security |defconfig | y | OK
CONFIG_COREDUMP |kconfig| harden_userspace | clipos | is not set | FAIL: "y"
CONFIG_PROC_MEM_NO_FORCE |kconfig| harden_userspace |a13xp0p0v | y | FAIL: is not found
CONFIG_ARCH_MMAP_RND_BITS |kconfig| harden_userspace |a13xp0p0v | 32 | OK
CONFIG_ARCH_MMAP_RND_COMPAT_BITS |kconfig| harden_userspace |a13xp0p0v | 16 | OK
CONFIG_X86_USER_SHADOW_STACK |kconfig| harden_userspace | kspp | y | OK
nokaslr |cmdline| self_protection |defconfig | is not set | OK: is not found
no_hash_pointers |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmep |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmap |cmdline| self_protection |defconfig | is not set | OK: is not found
dis_ucode_ldr |cmdline| self_protection |defconfig | is not set | OK: is not found
setcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
clearcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
nopti |cmdline| self_protection |defconfig | is not set | OK: is not found
nospec_store_bypass_disable |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v1 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v2 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_bhb |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nobti |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nopauth |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nomte |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nogcs |cmdline| self_protection |defconfig | is not set | OK: is not found
iommu.passthrough |cmdline| self_protection |defconfig | 0 | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH is "is not set"
rodata |cmdline| self_protection |defconfig | on | OK: rodata is not found
spectre_v2 |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_v2_user |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_bhi |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_store_bypass_disable |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
l1tf |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsx_async_abort |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
srbds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mmio_stale_data |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
retbleed |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_rstack_overflow |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
gather_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
reg_file_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsa |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
indirect_target_selection |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
vmscape |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
slab_merge |cmdline| self_protection | kspp | is not set | OK: is not found
slub_merge |cmdline| self_protection | kspp | is not set | OK: is not found
page_alloc.shuffle |cmdline| self_protection | kspp | 1 | FAIL: is not found
hash_pointers |cmdline| self_protection | kspp | always | FAIL: is not found
slab_nomerge |cmdline| self_protection | kspp | is present | FAIL: is not present
init_on_alloc |cmdline| self_protection | kspp | 1 | OK: CONFIG_INIT_ON_ALLOC_DEFAULT_ON is "y"
init_on_free |cmdline| self_protection | kspp | 1 | FAIL: is not found
hardened_usercopy |cmdline| self_protection | kspp | 1 | FAIL: is not found
slab_common.usercopy_fallback |cmdline| self_protection | kspp | is not set | OK: is not found
kfence.sample_interval |cmdline| self_protection | kspp | 100 | FAIL: is not found
lockdown |cmdline| self_protection | kspp |confidentiality| FAIL: is not found
module.sig_enforce |cmdline| self_protection | kspp | 1 | FAIL: is not found
efi |cmdline| self_protection | kspp |*disable_early_pci_dma*| FAIL: is not found
randomize_kstack_offset |cmdline| self_protection | kspp | 1 | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT is "y"
mitigations |cmdline| self_protection | kspp | auto,nosmt | FAIL: is not found
intel_iommu |cmdline| self_protection | kspp | on | OK: CONFIG_INTEL_IOMMU_DEFAULT_ON is "y"
iommu.strict |cmdline| self_protection | kspp | 1 | FAIL: is not found
pti |cmdline| self_protection | kspp | on | FAIL: is not found
cfi |cmdline| self_protection | kspp | kcfi | FAIL: is not found
iommu |cmdline| self_protection | clipos | force | FAIL: is not found
tsx |cmdline|cut_attack_surface|defconfig | off | OK: CONFIG_X86_INTEL_TSX_MODE_OFF is "y"
nosmt |cmdline|cut_attack_surface| kspp | is present | FAIL: is not present
vsyscall |cmdline|cut_attack_surface| kspp | none | FAIL: is not found
vdso32 |cmdline|cut_attack_surface| kspp | 0 | OK: CONFIG_COMPAT_VDSO is "is not set"
ia32_emulation |cmdline|cut_attack_surface| kspp | 0 | FAIL: is not found
debugfs |cmdline|cut_attack_surface| grsec | off | FAIL: is not found
sysrq_always_enabled |cmdline|cut_attack_surface|grapheneos| is not set | OK: is not found
bdev_allow_write_mounted |cmdline|cut_attack_surface|a13xp0p0v | 0 | FAIL: is not found
norandmaps |cmdline| harden_userspace |defconfig | is not set | OK: is not found
proc_mem.force_override |cmdline| harden_userspace |a13xp0p0v | never | FAIL: is not found
net.core.bpf_jit_harden |sysctl | self_protection | kspp | 2 | FAIL: is not found
vm.mmap_min_addr |sysctl | self_protection | kspp | 65536 | OK
kernel.oops_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "10000"
kernel.warn_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "0"
kernel.dmesg_restrict |sysctl |cut_attack_surface| kspp | 1 | OK
kernel.perf_event_paranoid |sysctl |cut_attack_surface| kspp | 3 | FAIL: "4"
dev.tty.ldisc_autoload |sysctl |cut_attack_surface| kspp | 0 | FAIL: "1"
kernel.kptr_restrict |sysctl |cut_attack_surface| kspp | 2 | FAIL: "1"
dev.tty.legacy_tiocsti |sysctl |cut_attack_surface| kspp | 0 | OK
user.max_user_namespaces |sysctl |cut_attack_surface| kspp | 0 | FAIL: "63417"
kernel.kexec_load_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.unprivileged_bpf_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "2"
vm.unprivileged_userfaultfd |sysctl |cut_attack_surface| kspp | 0 | OK
kernel.modules_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.io_uring_disabled |sysctl |cut_attack_surface| grsec | 2 | FAIL: "0"
kernel.sysrq |sysctl |cut_attack_surface|a13xp0p0v | 0 | FAIL: "176"
net.ipv4.icmp_ignore_bogus_error_responses|sysctl | network_security | cis | 1 | OK
net.ipv4.icmp_echo_ignore_broadcasts |sysctl | network_security | cis | 1 | OK
net.ipv4.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv4.conf.default.accept_source_route|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv6.conf.default.accept_source_route|sysctl | network_security | cis | 0 | OK
net.ipv4.tcp_syncookies |sysctl | network_security | cis | 1 | OK
net.ipv6.conf.all.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
fs.protected_symlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_hardlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_fifos |sysctl | harden_userspace | kspp | 2 | FAIL: "1"
fs.protected_regular |sysctl | harden_userspace | kspp | 2 | OK
fs.suid_dumpable |sysctl | harden_userspace | kspp | 0 | FAIL: "2"
kernel.randomize_va_space |sysctl | harden_userspace | kspp | 2 | OK
kernel.yama.ptrace_scope |sysctl | harden_userspace | kspp | 3 | FAIL: "1"
vm.mmap_rnd_bits |sysctl | harden_userspace |a13xp0p0v | 32 | FAIL: is not found
vm.mmap_rnd_compat_bits |sysctl | harden_userspace |a13xp0p0v | 16 | FAIL: is not found
[+] Config check is finished: 'OK' - 168 / 'FAIL' - 184
-g 인수를 사용하면 도구는 선택된 아키텍처에 대한 보안 강화 옵션이 포함된 Kconfig fragment를 생성합니다.
이 Kconfig fragment는 기존 Linux kernel config와 병합할 수 있습니다:``` $ ./bin/kernel-hardening-checker -g X86_64 > /tmp/fragment $ cd ~/linux-src/ $ ./scripts/kconfig/merge_config.sh .config /tmp/fragment Using .config as base Merging /tmp/fragment Value of CONFIG_BUG_ON_DATA_CORRUPTION is redefined by fragment /tmp/fragment: Previous value: # CONFIG_BUG_ON_DATA_CORRUPTION is not set New value: CONFIG_BUG_ON_DATA_CORRUPTION=y ...
## 감사
이 프로젝트의 [기여자][26]와 사용자 여러분께 감사드립니다!
## 질문과 답변
__Q:__ 이 모든 커널 파라미터가 Linux 커널 보안에 어떻게 영향을 미치나요?
__A:__ 이 질문에 답하기 위해 `kernel-hardening-checker` [권장 사항 소스][24]와 [Linux Kernel Defence Map][4] 및 그 참조 자료를 사용할 수 있습니다.
<br />
__Q:__ `CONFIG_USER_NS`를 비활성화하면 공격 표면이 어떻게 줄어드나요? 컨테이너에 필요합니다!
__A:__ 네, `CONFIG_USER_NS` 옵션은 사용자 공간 프로그램 간에 어느 정도 격리를 제공하지만, 도구는 __커널의__ 공격 표면을 줄이기 위해 비활성화를 권장합니다.
근거:
- 해당 LKML 토론에 대한 LWN 기사: https://lwn.net/Articles/673597/
- `CONFIG_USER_NS`와 보안에 관한 트위터 스레드: https://twitter.com/robertswiecki/status/1095447678949953541
- 사용자 네임스페이스를 활성화, 비활성화, 루트 전용으로 설정하는 것 사이의 절충에 대한 좋은 개요: https://github.com/NixOS/nixpkgs/pull/84522#issuecomment-614640601
<br />
__Q:__ KSPP와 CLIP OS는 `CONFIG_PANIC_ON_OOPS=y`를 권장합니다. 이 도구는 왜 동일하게 하지 않나요?
__A:__ 이 권장 사항을 지지할 수 없는 이유는 다음과 같습니다:
- 시스템 견고성을 감소시킵니다 (커널 oops는 프로덕션 시스템에서도 여전히 드문 상황이 아닙니다)
- 전체 시스템에 대한 서비스 거부 공격을 더 쉽게 허용합니다
다음과 같은 경우 `CONFIG_PANIC_ON_OOPS`를 활성화해야 합니다:
- 일반적인 워크로드 중에 커널이 oops를 만나지 않는 경우
- 사용 사례에서 가끔 시스템 재부팅이 문제가 되지 않는 경우
`kernel-hardening-checker`가 권장하는 좋은 절충안을 제시합니다:
- `CONFIG_BUG` kconfig 옵션을 활성화합니다. 프로세스 컨텍스트에서 커널 oops가 발생하면 문제를 일으키는/공격하는 프로세스가 종료됩니다. 다른 경우에는 커널 패닉이 발생하며, 이는 `CONFIG_PANIC_ON_OOPS=y`와 유사합니다.
- 예를 들어 sysctl 옵션 `kernel.oops_limit`와 `kernel.warn_limit`을 `100`으로 설정합니다. 한편으로 이 값은 쉬운 DoS를 허용하지 않습니다. 다른 한편으로는 많은 커널 경고나 oops를 생성하는 취약점 악용 시도를 놓치지 않을 만큼 너무 크지 않습니다.
<br />
__Q:__ `CONFIG_STATIC_USERMODEHELPER`를 활성화하면 GNU/Linux 시스템에서 다양한 문제가 발생하는 이유는 무엇인가요? 이 기능이 정말 필요한가요?
__A:__ Linux 커널 사용자 모드 헬퍼는 커널 익스플로잇에서 권한 상승에 사용될 수 있습니다 ([예시 1][9], [예시 2][10]). `CONFIG_STATIC_USERMODEHELPER`는 그 방법을 방지합니다. 그러나 사용자 공간에서 이에 상응하는 지원이 필요합니다: Tycho Andersen [@tych0][12]의 [예시 구현][11]을 참조하세요.
<br />
__Q:__ 이러한 보안 강화 기능의 성능 영향은 어떠한가요?
__A:__ 성능 영향은 시스템 워크로드에 따라 달라지므로 쉬운 질문이 아닙니다. Linux 보안 강화 기능의 성능 영향에 대한 자세한 평가는 TODO (이슈 [#66][21])에 있습니다. 이 분야에 몇 가지 흥미로운 연구가 있습니다:
- Ike Devolder [@BlackIkeEagle][7]이 몇 가지 성능 테스트를 수행하고 그 결과를 [이 글][8]에서 설명했습니다.
- Fabian Rauscher, Benedict Herzog, Timo Hönig, Daniel Gruss는 하드웨어 취약점 완화(CONFIG_CPU_MITIGATIONS)의 에너지 및 실행 시간 오버헤드를 설명하는 논문 ["Systematic Analysis of Kernel Security Performance and Energy Costs"][28]을 발표했습니다.
<br />
__Q:__ 내 커널에 하드웨어의 모든 transient execution 취약점 완화가 적용되어 있나요?
__A:__ 커널 구성을 확인하는 것만으로는 이 질문에 답하기에 충분하지 않습니다. Stéphane Lesimple [@speed47][14]이 유지 관리하는 [spectre-meltdown-checker][13] 도구를 사용하는 것을 적극 권장합니다.
<br />
__Q:__ 특정 Kconfig 옵션을 지원하는 커널 버전을 쉽게 확인할 수 있나요?
__A:__ 네. Giacomo Catenazzi [@cateee][19]의 [LKDDb][18] 프로젝트(Linux Kernel Driver Database)를 참조하세요. [kernel.org][20]의 `mainline` 또는 `stable` 트리나 사용자 정의 커널 소스에 사용할 수 있습니다.
<br />
__Q:__ `CONFIG_GCC_PLUGINS` 옵션이 커널 컴파일 중에 자동으로 비활성화되는 이유는 무엇인가요?
__A:__ 이는 gcc가 플러그인을 지원하지 않음을 의미합니다. 예를 들어 Ubuntu에서 `gcc-14`를 사용하는 경우 `gcc-14-plugin-dev` 패키지를 설치해 보면 도움이 될 것입니다.
[1]: https://kspp.github.io/Recommended_Settings
[2]: https://docs.clip-os.org/clipos/kernel.html#configuration
[3]: https://grsecurity.net/
[4]: https://github.com/a13xp0p0v/linux-kernel-defence-map
[5]: https://lwn.net/Articles/791863/
[6]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/38
[7]: https://github.com/BlackIkeEagle
[8]: https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[9]: https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html
[10]: https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html
[11]: https://github.com/tych0/huldufolk
[12]: https://github.com/tych0
[13]: https://github.com/speed47/spectre-meltdown-checker
[14]: https://github.com/speed47
[15]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/53
[16]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/54
[17]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/62
[18]: https://cateee.net/lkddb/web-lkddb/
[19]: https://github.com/cateee/lkddb
[20]: https://kernel.org/
[21]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/66
[22]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/56
[23]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues?q=label:kernel_maintainer_feedback
[24]: https://github.com/a13xp0p0v/kernel-hardening-checker#motivation
[25]: https://grapheneos.org/features
[26]: https://github.com/a13xp0p0v/kernel-hardening-checker/graphs/contributors
[27]: https://learn.cisecurity.org/benchmarks
[28]: https://dl.acm.org/doi/epdf/10.1145/3708821.3736197