Kai Ole Hartwig

name of the term: Kernel Hardening
descriptions of the term:

Definition

Definition. The sum of measures that reduce the attack surface and exploit tolerance of a Linux kernel: enabling protection mechanisms (KASLR, SMEP/SMAP, BTI, stack protector), restricting subsystems (kernel.unprivileged_userns_clone, kernel.kptr_restrict), mitigations for CPU vulnerabilities and LSMs such as SELinux or AppArmor.

Why it matters. Even if a kernel patch has not been rolled out yet, a hardened kernel can slow down or prevent many exploits. Hardening is not a one-off step but part of running worker nodes.

Related. Kernel LPE, Container Escape, Pod Security Standards, Runtime Security

Type of term: definition
Language of the term (2 char ISO code): en
Back