
리눅스 커널의 보안 강화 옵션을 확인하는 도구
(이전 명칭: kconfig-hardened-check)
Linux 커널에는 다양한 보안 강화 옵션이 있습니다. 대부분의 주요 배포판에서는 이러한 옵션을 기본적으로 활성화하지 않습니다. 시스템을 더 안전하게 만들기 위해 직접 이러한 옵션을 활성화해야 합니다.
하지만 설정을 수동으로 확인하는 것을 좋아하는 사람은 없습니다. 그러니 컴퓨터가 그 일을 하게 합시다!
kernel-hardening-checker (이전 명칭 kconfig-hardened-check)는 Linux 커널의 보안 강화 옵션을 확인하는 도구입니다.
라이선스: GPL-3.0.
kernel-hardening-checker는 다음을 확인할 수 있습니다:
지원 아키텍처:
보안 강화 권장 사항은 다음을 기반으로 합니다:
또한 [Linux 커널 방어 맵][4]을 만들었습니다. 이는 보안 강화 기능과 해당 취약점 클래스 또는 익스플로잇 기술 간의 관계를 그래픽으로 표현한 것입니다.
Linux 커널 보안 매개변수를 변경하면 시스템 성능과 사용자 공간 소프트웨어의 기능에 영향을 줄 수 있습니다. 따라서 이러한 매개변수를 설정할 때는 Linux 기반 정보 시스템의 위협 모델을 고려하고 일반적인 워크로드를 철저히 테스트하십시오.
여러 가지 옵션이 있습니다:
pip을 사용하여 이 Git 저장소에서 패키지를 설치할 수 있습니다:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
외부 관리 환경으로 인해 오류가 발생하면 python3 -m venv를 사용하여 가상 환경을 만드십시오.
일부 GNU/Linux 배포판의 패키지 관리자를 통해 kernel-hardening-checker 패키지를 설치할 수 있습니다. https://repology.org/project/kernel-hardening-checker/versions 참조
또는 클론된 저장소에서 설치 없이 ./bin/kernel-hardening-checker를 실행할 수 있습니다.
$ ./bin/kernel-hardening-checker -h usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}] [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE] [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}] [-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options: -h, --help show this help message and exit --version show program's version number and exit -m, --mode {verbose,json,show_ok,show_fail} select a special output mode instead of the default one -a, --autodetect autodetect and check the security hardening options of the running kernel -c, --config CONFIG check the security hardening options in a Kconfig file (also supports *.gz files) -v, --kernel-version KERNEL_VERSION extract the kernel version from a version file (such as /proc/version) instead of using a Kconfig file -l, --cmdline CMDLINE check the security hardening options in a kernel command line file (such as /proc/cmdline) -s, --sysctl SYSCTL check the security hardening options in a sysctl output file (the result of "sudo sysctl -a > file") -p, --print {X86_64,X86_32,ARM64,ARM,RISCV} print security hardening recommendations for the selected architecture -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV} generate a Kconfig fragment containing the security hardening options for the selected architecture
## 출력 모드
- 기본 출력 모드를 위한 `-m` 인수 없음 (아래 예시 참고)
- `-m verbose` 추가 정보 출력:
- 해당 검사가 없는 구성 옵션들
- AND/OR을 사용하는 복잡한 검사의 내부 구조, 예시:
```
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
```
- `-m json` 결과를 JSON 형식으로 출력 (`kernel-hardening-checker`를 다른 도구와 결합하기 위해)
- `-m show_ok` 성공한 검사만 표시
- `-m show_fail` 실패한 검사만 표시