(原名 kconfig-hardened-check)
Linux 内核拥有大量安全加固选项。大多数主流发行版并未启用其中的许多选项。我们必须自行启用这些选项,以使我们的系统更加安全。
但没人喜欢手动检查配置。所以让计算机来完成它们的工作吧!
kernel-hardening-checker(原名 kconfig-hardened-check)是一款用于检查 Linux 内核安全加固选项的工具。
许可证:GPL-3.0。
kernel-hardening-checker 支持检查:
支持的架构:
安全加固建议基于:
我还创建了 [Linux 内核防御地图][4],这是一张图形化表示,展示了安全加固特性与相应漏洞类别或利用技术之间的关系。
请注意,更改 Linux 内核安全参数可能会影响系统性能和用户空间软件的功能。因此,在设置这些参数时,请考虑您的基于 Linux 的信息系统的威胁模型,并彻底测试其典型负载。
有多种选择:
您可以使用 pip 从此 Git 仓库安装包:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
如果遇到因外部管理环境导致的错误,请使用 python3 -m venv 创建虚拟环境。
您可以在某些 GNU/Linux 发行版上通过包管理器安装 kernel-hardening-checker 包。参见 https://repology.org/project/kernel-hardening-checker/versions
或者,您可以直接从克隆后的仓库中运行 ./bin/kernel-hardening-checker,无需安装。
$ ./bin/kernel-hardening-checker -h usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}] [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE] [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}] [-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options: -h, --help show this help message and exit --version show program's version number and exit -m, --mode {verbose,json,show_ok,show_fail} select a special output mode instead of the default one -a, --autodetect autodetect and check the security hardening options of the running kernel -c, --config CONFIG check the security hardening options in a Kconfig file (also supports *.gz files) -v, --kernel-version KERNEL_VERSION extract the kernel version from a version file (such as /proc/version) instead of using a Kconfig file -l, --cmdline CMDLINE check the security hardening options in a kernel command line file (such as /proc/cmdline) -s, --sysctl SYSCTL check the security hardening options in a sysctl output file (the result of "sudo sysctl -a > file") -p, --print {X86_64,X86_32,ARM64,ARM,RISCV} print security hardening recommendations for the selected architecture -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV} generate a Kconfig fragment containing the security hardening options for the selected architecture
## Output modes
- 无 `-m` 参数时使用默认输出模式(参见下方示例)
- `-m verbose` 用于打印额外信息:
- 没有对应检查的配置选项
- 含有 AND/OR 的复杂检查的内部结构,如下所示:
```
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
```
- `-m json` 用于以 JSON 格式打印结果(用于将 `kernel-hardening-checker` 与其他工具结合使用)
- `-m show_ok` 用于仅显示成功的检查
- `-m show_fail` 用于仅显示失败的检查
## Example output```
$ ./bin/kernel-hardening-checker -a
[+] Going to autodetect and check the security hardening options of the running kernel
[+] Detected version of the running kernel: (6, 11, 0)
[+] Detected kconfig file of the running kernel: /boot/config-6.11.0-1007-oem
[+] Detected cmdline parameters of the running kernel: /proc/cmdline
[+] Saved sysctls to a temporary file /tmp/sysctl-at_0n9si
[+] Detected architecture: X86_64
[+] Detected compiler: GCC 130200
[!] WARNING: sysctl options available for root are not found in /tmp/sysctl-at_0n9si, try checking the output of "sudo sysctl -a"
=========================================================================================================================
option_name | type | reason | decision |desired_val | check_result
=========================================================================================================================
CONFIG_BUG |kconfig| self_protection |defconfig | y | OK
CONFIG_SLUB_DEBUG |kconfig| self_protection |defconfig | y | OK
CONFIG_THREAD_INFO_IN_TASK |kconfig| self_protection |defconfig | y | OK
CONFIG_IOMMU_DEFAULT_PASSTHROUGH |kconfig| self_protection |defconfig | is not set | OK
CONFIG_IOMMU_SUPPORT |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR_STRONG |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_KERNEL_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_MODULE_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_REFCOUNT_FULL |kconfig| self_protection |defconfig | y | OK: version >= (5, 4, 208)
CONFIG_INIT_STACK_ALL_ZERO |kconfig| self_protection |defconfig | y | OK
CONFIG_CPU_MITIGATIONS |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOMIZE_BASE |kconfig| self_protection |defconfig | y | OK
CONFIG_VMAP_STACK |kconfig| self_protection |defconfig | y | OK
CONFIG_LSM_MMAP_MIN_ADDR |kconfig| self_protection |defconfig | 65536 | FAIL: "0"
CONFIG_DEBUG_WX |kconfig| self_protection |defconfig | y | OK
CONFIG_WERROR |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_X86_MCE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_V1 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SPECTRE_V2 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SSB |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MICROCODE |kconfig| self_protection |defconfig | y | OK
CONFIG_MICROCODE_INTEL |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_MICROCODE_AMD |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_X86_SMAP |kconfig| self_protection |defconfig | y | OK: version >= (5, 19, 0)
CONFIG_X86_UMIP |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_INTEL |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_AMD |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_RETPOLINE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_GDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RFDS |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_BHI |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_MDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TAA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_MMIO_STALE_DATA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_L1TF |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RETBLEED |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SRBDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TSA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_VMSCAPE |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_RANDOMIZE_MEMORY |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_KERNEL_IBT |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_MITIGATION_RETHUNK |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_PAGE_TABLE_ISOLATION|kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_UNRET_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_CALL_DEPTH_TRACKING |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBPB_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBRS_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SRSO |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_ITS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_INTEL_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_AMD_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOM_KMALLOC_CACHES |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_MERGE_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: "y"
CONFIG_BUG_ON_DATA_CORRUPTION |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SLAB_FREELIST_HARDENED |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_FREELIST_RANDOM |kconfig| self_protection | kspp | y | OK
CONFIG_SHUFFLE_PAGE_ALLOCATOR |kconfig| self_protection | kspp | y | OK
CONFIG_FORTIFY_SOURCE |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_VIRTUAL |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_ALLOC_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_STATIC_USERMODEHELPER |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SECURITY_LOCKDOWN_LSM |kconfig| self_protection | kspp | y | OK
CONFIG_LSM |kconfig| self_protection | kspp | *lockdown* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LOCKDOWN_LSM_EARLY |kconfig| self_protection | kspp | y | OK
CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY|kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_DEBUG_SG |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_ZERO_CALL_USED_REGS |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_CREDENTIALS |kconfig| self_protection | kspp | y | OK: version >= (6, 6, 8)
CONFIG_DEBUG_NOTIFIERS |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_KFENCE |kconfig| self_protection | kspp | y | OK
CONFIG_KFENCE_SAMPLE_INTERVAL |kconfig| self_protection | kspp | 100 | FAIL: "0"
CONFIG_RANDSTRUCT_FULL |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY |kconfig| self_protection | kspp | y | OK
CONFIG_HARDENED_USERCOPY_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY_FALLBACK |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_HARDENED_USERCOPY_PAGESPAN |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_GCC_PLUGIN_LATENT_ENTROPY |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_MODULE_SIG |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_ALL |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_SHA512 |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_FORCE |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_FREE_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_EFI_DISABLE_PCI_DMA |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RESET_ATTACK_MITIGATION |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_BOUNDS |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_LOCAL_BOUNDS |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_UBSAN_TRAP |kconfig| self_protection | kspp | y | FAIL: CONFIG_UBSAN_ENUM is not "is not set"
CONFIG_UBSAN_SANITIZE_ALL |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_SCHED_STACK_END_CHECK |kconfig| self_protection | kspp | y | OK
CONFIG_KSTACK_ERASE |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_KSTACK_ERASE_METRICS |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_KSTACK_ERASE_RUNTIME_DISABLE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_SCHED_CORE |kconfig| self_protection | kspp | y | OK
CONFIG_LIST_HARDENED |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT|kconfig| self_protection | kspp | y | OK
CONFIG_PAGE_TABLE_CHECK |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_PAGE_TABLE_CHECK_ENFORCED |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_DEFAULT_MMAP_MIN_ADDR |kconfig| self_protection | kspp | 65536 | OK
CONFIG_HW_RANDOM_TPM |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_CLANG |kconfig| self_protection | kspp | y | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_CFI_PERMISSIVE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_IOMMU_DEFAULT_DMA_STRICT |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INTEL_IOMMU_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_AUTO_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CFI_AUTO_DEFAULT is not present
CONFIG_MITIGATION_SLS |kconfig| self_protection | kspp | y | OK
CONFIG_INTEL_IOMMU_SVM |kconfig| self_protection | kspp | y | OK
CONFIG_AMD_IOMMU_V2 |kconfig| self_protection | kspp | y | OK: version >= (6, 7, 0)
CONFIG_SECURITY |kconfig| security_policy |defconfig | y | OK
CONFIG_SECURITY_YAMA |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *yama* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LANDLOCK |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *landlock* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_SELINUX_DISABLE |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_BOOTPARAM |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_SELINUX_DEVELOP |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_WRITABLE_HOOKS |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_DEBUG |kconfig| security_policy | kspp | is not set | OK
CONFIG_SECURITY_SELINUX |kconfig| security_policy |a13xp0p0v | y | OK
CONFIG_LSM |kconfig| security_policy |a13xp0p0v | *selinux* | OK: "apparmor" is in CONFIG_LSM
CONFIG_SECCOMP |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECCOMP_FILTER |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_BPF_UNPRIV_DEFAULT_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_X86_INTEL_TSX_MODE_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECURITY_DMESG_RESTRICT |kconfig|cut_attack_surface| kspp | y | OK
CONFIG_ACPI_CUSTOM_METHOD |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_COMPAT_BRK |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DEVKMEM |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_BINFMT_MISC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_INET_DIAG |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_KEXEC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_PROC_KCORE |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_LEGACY_PTYS |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_HIBERNATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IA32_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_X32 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_X32_ABI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODIFY_LDT_SYSCALL |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_OABI_COMPAT |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_MSR |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_LEGACY_TIOCSTI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODULE_FORCE_LOAD |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_M486 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_MODULES |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IO_STRICT_DEVMEM |kconfig|cut_attack_surface| kspp | y | FAIL: "is not set"
CONFIG_LDISC_AUTOLOAD |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_VSYSCALL_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT_VDSO |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DRM_LEGACY |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_FB |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_VT |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_BLK_DEV_FD |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_BLK_DEV_FD_RAWCMD |kconfig|cut_attack_surface|maintainer| is not set | OK
CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_N_GSM |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_ZSMALLOC_STAT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DEBUG_KMEMLEAK |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BINFMT_AOUT |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_KPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_UPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_GENERIC_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_FUNCTION_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_STACK_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HIST_TRIGGERS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_IO_TRACE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_VMCORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_PAGE_MONITOR |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USELIB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_CHECKPOINT_RESTORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USERFAULTFD |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HWPOISON_INJECT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MEM_SOFT_DIRTY |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEVPORT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEBUG_FS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_NOTIFIER_ERROR_INJECTION |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_FAIL_FUTEX |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PUNIT_ATOM_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_ACPI_CONFIGFS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_EDAC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DRM_I915_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DVB_C8SECTPFE |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MTD_SLRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MTD_PHRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IO_URING |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCMP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_RSEQ |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_LATENCYTOP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCOV |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_PROVIDE_OHCI1394_DMA_INIT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_SUNRPC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_X86_16BIT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_UBLK |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_SMB_SERVER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_XFS_ONLINE_SCRUB_STATS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_CACHESTAT_SYSCALL |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PREEMPTIRQ_TRACEPOINTS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_ENABLE_DEFAULT_TRACERS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PROVE_LOCKING |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_TEST_DEBUG_VIRTUAL |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MPTCP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_TLS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_TIPC |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IP_SCTP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_KGDB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PTDUMP_DEBUGFS |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_X86_PTDUMP |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_DEBUG_CLOSURES |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BCACHE_CLOSURES_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_STAGING |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KSM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KALLSYMS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KEXEC_FILE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_CRASH_DUMP |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_USER_NS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_X86_CPUID |kconfig|cut_attack_surface| clipos | is not set | FAIL: "m"
CONFIG_X86_IOPL_IOPERM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_ACPI_TABLE_UPGRADE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_EFI_CUSTOM_SSDT_OVERLAYS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_AIO |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ_SERIAL |kconfig|cut_attack_surface|grapheneos| is not set | FAIL: "y"
CONFIG_EFI_TEST |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "m"
CONFIG_MMIOTRACE_TEST |kconfig|cut_attack_surface| lockdown | is not set | OK
CONFIG_KPROBES |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_BPF_SYSCALL |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_MMIOTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_LIVEPATCH |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_IP_DCCP |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_FTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_VIDEO_VIVID |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_INPUT_EVBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_CORESIGHT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_XFS_SUPPORT_V4 |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_BLK_DEV_WRITE_MOUNTED |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_FAULT_INJECTION |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_ARM_PTDUMP_DEBUGFS |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_ARM_PTDUMP |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_SECCOMP_CACHE_DEBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_CRASH_DM_CRYPT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_LKDTM |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_TRIM_UNUSED_KSYMS |kconfig|cut_attack_surface|a13xp0p0v | y | FAIL: "is not set"
CONFIG_SYN_COOKIES |kconfig| network_security |defconfig | y | OK
CONFIG_COREDUMP |kconfig| harden_userspace | clipos | is not set | FAIL: "y"
CONFIG_PROC_MEM_NO_FORCE |kconfig| harden_userspace |a13xp0p0v | y | FAIL: is not found
CONFIG_ARCH_MMAP_RND_BITS |kconfig| harden_userspace |a13xp0p0v | 32 | OK
CONFIG_ARCH_MMAP_RND_COMPAT_BITS |kconfig| harden_userspace |a13xp0p0v | 16 | OK
CONFIG_X86_USER_SHADOW_STACK |kconfig| harden_userspace | kspp | y | OK
nokaslr |cmdline| self_protection |defconfig | is not set | OK: is not found
no_hash_pointers |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmep |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmap |cmdline| self_protection |defconfig | is not set | OK: is not found
dis_ucode_ldr |cmdline| self_protection |defconfig | is not set | OK: is not found
setcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
clearcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
nopti |cmdline| self_protection |defconfig | is not set | OK: is not found
nospec_store_bypass_disable |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v1 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v2 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_bhb |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nobti |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nopauth |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nomte |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nogcs |cmdline| self_protection |defconfig | is not set | OK: is not found
iommu.passthrough |cmdline| self_protection |defconfig | 0 | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH is "is not set"
rodata |cmdline| self_protection |defconfig | on | OK: rodata is not found
spectre_v2 |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_v2_user |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_bhi |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_store_bypass_disable |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
l1tf |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsx_async_abort |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
srbds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mmio_stale_data |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
retbleed |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_rstack_overflow |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
gather_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
reg_file_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsa |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
indirect_target_selection |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
vmscape |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
slab_merge |cmdline| self_protection | kspp | is not set | OK: is not found
slub_merge |cmdline| self_protection | kspp | is not set | OK: is not found
page_alloc.shuffle |cmdline| self_protection | kspp | 1 | FAIL: is not found
hash_pointers |cmdline| self_protection | kspp | always | FAIL: is not found
slab_nomerge |cmdline| self_protection | kspp | is present | FAIL: is not present
init_on_alloc |cmdline| self_protection | kspp | 1 | OK: CONFIG_INIT_ON_ALLOC_DEFAULT_ON is "y"
init_on_free |cmdline| self_protection | kspp | 1 | FAIL: is not found
hardened_usercopy |cmdline| self_protection | kspp | 1 | FAIL: is not found
slab_common.usercopy_fallback |cmdline| self_protection | kspp | is not set | OK: is not found
kfence.sample_interval |cmdline| self_protection | kspp | 100 | FAIL: is not found
lockdown |cmdline| self_protection | kspp |confidentiality| FAIL: is not found
module.sig_enforce |cmdline| self_protection | kspp | 1 | FAIL: is not found
efi |cmdline| self_protection | kspp |*disable_early_pci_dma*| FAIL: is not found
randomize_kstack_offset |cmdline| self_protection | kspp | 1 | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT is "y"
mitigations |cmdline| self_protection | kspp | auto,nosmt | FAIL: is not found
intel_iommu |cmdline| self_protection | kspp | on | OK: CONFIG_INTEL_IOMMU_DEFAULT_ON is "y"
iommu.strict |cmdline| self_protection | kspp | 1 | FAIL: is not found
pti |cmdline| self_protection | kspp | on | FAIL: is not found
cfi |cmdline| self_protection | kspp | kcfi | FAIL: is not found
iommu |cmdline| self_protection | clipos | force | FAIL: is not found
tsx |cmdline|cut_attack_surface|defconfig | off | OK: CONFIG_X86_INTEL_TSX_MODE_OFF is "y"
nosmt |cmdline|cut_attack_surface| kspp | is present | FAIL: is not present
vsyscall |cmdline|cut_attack_surface| kspp | none | FAIL: is not found
vdso32 |cmdline|cut_attack_surface| kspp | 0 | OK: CONFIG_COMPAT_VDSO is "is not set"
ia32_emulation |cmdline|cut_attack_surface| kspp | 0 | FAIL: is not found
debugfs |cmdline|cut_attack_surface| grsec | off | FAIL: is not found
sysrq_always_enabled |cmdline|cut_attack_surface|grapheneos| is not set | OK: is not found
bdev_allow_write_mounted |cmdline|cut_attack_surface|a13xp0p0v | 0 | FAIL: is not found
norandmaps |cmdline| harden_userspace |defconfig | is not set | OK: is not found
proc_mem.force_override |cmdline| harden_userspace |a13xp0p0v | never | FAIL: is not found
net.core.bpf_jit_harden |sysctl | self_protection | kspp | 2 | FAIL: is not found
vm.mmap_min_addr |sysctl | self_protection | kspp | 65536 | OK
kernel.oops_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "10000"
kernel.warn_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "0"
kernel.dmesg_restrict |sysctl |cut_attack_surface| kspp | 1 | OK
kernel.perf_event_paranoid |sysctl |cut_attack_surface| kspp | 3 | FAIL: "4"
dev.tty.ldisc_autoload |sysctl |cut_attack_surface| kspp | 0 | FAIL: "1"
kernel.kptr_restrict |sysctl |cut_attack_surface| kspp | 2 | FAIL: "1"
dev.tty.legacy_tiocsti |sysctl |cut_attack_surface| kspp | 0 | OK
user.max_user_namespaces |sysctl |cut_attack_surface| kspp | 0 | FAIL: "63417"
kernel.kexec_load_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.unprivileged_bpf_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "2"
vm.unprivileged_userfaultfd |sysctl |cut_attack_surface| kspp | 0 | OK
kernel.modules_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.io_uring_disabled |sysctl |cut_attack_surface| grsec | 2 | FAIL: "0"
kernel.sysrq |sysctl |cut_attack_surface|a13xp0p0v | 0 | FAIL: "176"
net.ipv4.icmp_ignore_bogus_error_responses|sysctl | network_security | cis | 1 | OK
net.ipv4.icmp_echo_ignore_broadcasts |sysctl | network_security | cis | 1 | OK
net.ipv4.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv4.conf.default.accept_source_route|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv6.conf.default.accept_source_route|sysctl | network_security | cis | 0 | OK
net.ipv4.tcp_syncookies |sysctl | network_security | cis | 1 | OK
net.ipv6.conf.all.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
fs.protected_symlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_hardlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_fifos |sysctl | harden_userspace | kspp | 2 | FAIL: "1"
fs.protected_regular |sysctl | harden_userspace | kspp | 2 | OK
fs.suid_dumpable |sysctl | harden_userspace | kspp | 0 | FAIL: "2"
kernel.randomize_va_space |sysctl | harden_userspace | kspp | 2 | OK
kernel.yama.ptrace_scope |sysctl | harden_userspace | kspp | 3 | FAIL: "1"
vm.mmap_rnd_bits |sysctl | harden_userspace |a13xp0p0v | 32 | FAIL: is not found
vm.mmap_rnd_compat_bits |sysctl | harden_userspace |a13xp0p0v | 16 | FAIL: is not found
[+] Config check is finished: 'OK' - 168 / 'FAIL' - 184
通过 -g 参数,该工具为目标架构生成包含安全强化选项的 Kconfig 片段。
此 Kconfig 片段可与现有 Linux 内核配置合并:``` $ ./bin/kernel-hardening-checker -g X86_64 > /tmp/fragment $ cd ~/linux-src/ $ ./scripts/kconfig/merge_config.sh .config /tmp/fragment Using .config as base Merging /tmp/fragment Value of CONFIG_BUG_ON_DATA_CORRUPTION is redefined by fragment /tmp/fragment: Previous value: # CONFIG_BUG_ON_DATA_CORRUPTION is not set New value: CONFIG_BUG_ON_DATA_CORRUPTION=y ...
## 感谢
感谢本项目的[贡献者][26]和用户!
## 问答
__问:__ 所有这些内核参数如何影响 Linux 内核安全性?
__答:__ 要回答这个问题,你可以使用 `kernel-hardening-checker` 的[建议来源][24]以及[Linux 内核防御地图][4]及其参考文献。
<br />
__问:__ 禁用 `CONFIG_USER_NS` 如何减少攻击面?容器需要它!
__答:__ 是的,`CONFIG_USER_NS` 选项为用户空间程序提供了一定的隔离,但该工具建议禁用它以减少__内核__的攻击面。
理由如下:
- 一篇关于相应 LKML 讨论的 LWN 文章:https://lwn.net/Articles/673597/
- 一个关于 `CONFIG_USER_NS` 和安全的 Twitter 话题:https://twitter.com/robertswiecki/status/1095447678949953541
- 一份关于启用、禁用以及仅限 root 使用用户命名空间的权衡概述:https://github.com/NixOS/nixpkgs/pull/84522#issuecomment-614640601
<br />
__问:__ KSPP 和 CLIP OS 建议设置 `CONFIG_PANIC_ON_OOPS=y`。为什么这个工具不这样做?
__答:__ 我不能支持这个建议,因为:
- 它降低了系统的健壮性(即使在生产系统上,内核 oops 仍然不是罕见情况)
- 它使整个系统更容易受到拒绝服务攻击
你应该启用 `CONFIG_PANIC_ON_OOPS`,如果:
- 你的内核在典型工作负载下不会遇到 oops
- 偶尔的系统重启在你的用例中不是问题
我看到一个好的折衷方案,`kernel-hardening-checker` 推荐如下:
- 启用 `CONFIG_BUG` kconfig 选项。如果内核 oops 发生在进程上下文,违规/攻击进程会被杀死。在其他情况下,内核会崩溃,这与 `CONFIG_PANIC_ON_OOPS=y` 类似。
- 将 sysctl 选项 `kernel.oops_limit` 和 `kernel.warn_limit` 设置为 `100`。一方面,这个值不会让 DoS 变得容易。另一方面,它又不会太大以至于错过产生大量内核警告或 oops 的漏洞利用尝试。
<br />
__问:__ 为什么启用 `CONFIG_STATIC_USERMODEHELPER` 会在我的 GNU/Linux 系统中破坏各种功能?我真的需要这个特性吗?
__答:__ Linux 内核的用户模式助手可用于内核提权漏洞利用([示例1][9],[示例2][10])。`CONFIG_STATIC_USERMODEHELPER` 可以防止这种方法。但它需要用户空间的相应支持:参见 Tycho Andersen [@tych0][12] 的[示例实现][11]。
<br />
__问:__ 这些安全加固特性对性能有什么影响?
__答:__ 这不是一个简单的问题,因为性能影响取决于系统的工作负载。对 Linux 安全加固特性性能影响的详细评估已在 TODO 中(议题[#66][21])。该领域有一些有趣的工作:
- Ike Devolder [@BlackIkeEagle][7] 进行了一些性能测试,并在[这篇文章][8]中描述了结果。
- Fabian Rauscher, Benedict Herzog, Timo Hönig 和 Daniel Gruss 发表了一篇文章["Systematic Analysis of Kernel Security Performance and Energy Costs"][28],描述了硬件漏洞缓解措施(CONFIG_CPU_MITIGATIONS)的能耗和运行时开销。
<br />
__问:__ 我的内核是否具备所有针对硬件瞬态执行漏洞的缓解措施?
__答:__ 仅检查内核配置不足以回答这个问题。我强烈建议使用由 Stéphane Lesimple [@speed47][14] 维护的 [spectre-meltdown-checker][13] 工具。
<br />
__问:__ 我能否轻松检查哪些内核版本支持某个 Kconfig 选项?
__答:__ 可以。参见 Giacomo Catenazzi [@cateee][19] 的 [LKDDb][18] 项目(Linux 内核驱动数据库)。你可以用它查询 [kernel.org][20] 的 `mainline` 或 `stable` 树,或者你自己的内核源码。
<br />
__问:__ 为什么 `CONFIG_GCC_PLUGINS` 选项在内核编译过程中会自动禁用?
__答:__ 这意味着你的 gcc 不支持插件。例如,如果你在 Ubuntu 上使用 `gcc-14`,尝试安装 `gcc-14-plugin-dev` 包,它应该会有所帮助。
[1]: https://kspp.github.io/Recommended_Settings
[2]: https://docs.clip-os.org/clipos/kernel.html#configuration
[3]: https://grsecurity.net/
[4]: https://github.com/a13xp0p0v/linux-kernel-defence-map
[5]: https://lwn.net/Articles/791863/
[6]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/38
[7]: https://github.com/BlackIkeEagle
[8]: https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[9]: https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html
[10]: https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html
[11]: https://github.com/tych0/huldufolk
[12]: https://github.com/tych0
[13]: https://github.com/speed47/spectre-meltdown-checker
[14]: https://github.com/speed47
[15]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/53
[16]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/54
[17]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/62
[18]: https://cateee.net/lkddb/web-lkddb/
[19]: https://github.com/cateee/lkddb
[20]: https://kernel.org/
[21]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/66
[22]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/56
[23]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues?q=label:kernel_maintainer_feedback
[24]: https://github.com/a13xp0p0v/kernel-hardening-checker#motivation
[25]: https://grapheneos.org/features
[26]: https://github.com/a13xp0p0v/kernel-hardening-checker/graphs/contributors
[27]: https://learn.cisecurity.org/benchmarks
[28]: https://dl.acm.org/doi/epdf/10.1145/3708821.3736197