SEC-301 · Kernel Security · Advanced
LSM, SELinux & AppArmor — full syllabus
Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced.
Who this course is for
System and security engineers who must confine real services with mandatory access control — and debug the denials without reaching for permissive mode.
Prerequisites
- Solid Linux administration
- C reading ability for the LSM hook walk-through
- A VM you can break (provided)
Course outline
Day 1 — The LSM framework
- Why discretionary access control is not enough: confused deputies and ambient authority
- The LSM hook architecture: where hooks live and what they can decide
- Stacking and ordering: which LSM wins when several are loaded
- Major vs minor LSMs; enabling and ordering at boot with lsm=
- Security blobs: the inode, task and cred security fields
Day 2 — SELinux
- Type enforcement: types, domains and the allow rule
- Transitions: domain and file transitions, entrypoints and the exec path
- Roles, users and MLS in one honest hour
- Policy modules: building and loading your own with semodule
- Debugging with audit.log, ausearch and audit2allow — and when audit2allow lies
Day 3 — AppArmor and confining a real service
- AppArmor profiles: paths vs labels, and the trade-offs that follow
- Profile modes: enforce, complain, kill, unconfined; aa-status and aa-genprof
- File, capability, network and mount rules in practice
- Choosing SELinux vs AppArmor for a product: maintenance, tooling and team skills
- Confining a real service end to end: from strace-derived profile to enforced and tested
Hands-on labs
- Lab: Inspect LSM hooks in the source and trace a permission decision with ftrace or bpftrace
- Lab: Boot a VM with different LSM stacking orders and document the behavioural difference
- Lab: Write and load an SELinux policy module for a custom daemon; fix the denials from audit logs
- Lab: Build an AppArmor profile for a network service, then attack it and close the gaps
- Lab: Take one service from unconfined to enforced with a denial-log trail proving each step
Capstone project
Confine a provided multi-process service end to end: choose SELinux or AppArmor with a written justification, develop the policy iteratively from audit logs, demonstrate that legitimate function survives and that two scripted attacks are now denied — and deliver the policy plus the denial-log evidence trail.
What you leave with
- A working model of LSM hooks and stacking order
- SELinux policy-module authoring and audit-log debugging skills
- AppArmor profiling from strace and aa-genprof to enforcement
- A defensible SELinux-vs-AppArmor selection method
- An enforced confinement for a real service, with evidence
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 22 Nov – 24 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 3 of 14 | SAR 8,100until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | Kuwait CityIn person · Al Hamra Tower | 8 of 14 | KWD 670until 30 Oct | ||
| 6 Dec – 8 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 3 of 14 | OMR 830until 6 Nov | ||
| 6 Dec – 13 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 11 of 20 | US$1,580until 6 Nov | ||
| 7 Dec – 9 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 8 of 14 | CAD 2,930until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 3 of 14 | CAD 2,930until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 16 of 20 | US$1,580until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 5 of 20 | US$1,580until 14 Nov | ||
| 21 Dec – 23 Dec 20263 full days | LondonIn person · Shoreditch Works | 8 of 14 | GBP 1,680until 21 Nov | ||
| 21 Dec – 23 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 3 of 14 | EUR 1,990until 21 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.