SEC-320 · Kernel Security · Advanced
Integrity: IMA/EVM & dm-verity — full syllabus
Measuring and verifying what runs on the system, from block device to individual file.
Who this course is for
Embedded and platform engineers building systems that must prove what they are running — from the block device up to individual files.
Prerequisites
- Kernel build and boot experience (QEMU acceptable)
- Basic public-key cryptography concepts
- Block-device and initramfs familiarity
Course outline
Day 1 — dm-verity
- Merkle-tree verification of read-only filesystems: layout, hash tree and root hash
- Creating verity images with veritysetup; booting them from initramfs
- Error handling: what happens on corruption and how to test it
- Root-hash distribution: where the trust anchor lives (cmdline, TPM, signed image)
- dm-verity with forward error correction for flash-level bit rot
Day 2 — IMA and EVM
- IMA measurement: what gets hashed and where the measurement list lives
- IMA appraisal: enforcing signatures on file access, and its failure modes
- IMA policy: writing measurement and appraisal rules for a real rootfs
- EVM: protecting extended attributes against offline modification
- Key management: kernel keyrings, trusted and encrypted keys, and TPM-backed options
Day 3 — The verified boot-to-runtime chain
- Chain of trust from boot ROM to kernel: what each link must prove
- Measured boot vs verified boot, and where the TPM fits (swtpm for the labs)
- Assembling dm-verity plus IMA/EVM into one coherent architecture
- Update and recovery: keeping the chain intact across A/B updates
- Writing the integrity architecture document an assessor will ask for
Hands-on labs
- Lab: Build a dm-verity image, boot it in QEMU, corrupt a block and observe the failure behaviour
- Lab: Change the root hash and prove the system refuses to boot — then restore it
- Lab: Write an IMA policy, boot with it and inspect the measurement list after exercising the system
- Lab: Enable IMA appraisal on a test rootfs and show that a modified file is refused
- Lab: Seal a trusted key against a swtpm and use it in the EVM setup
Capstone project
Assemble and demonstrate a verified boot-to-runtime chain in QEMU: a dm-verity rootfs anchored to a known root hash, IMA measurement and appraisal policy on top, EVM protecting the attributes, and trusted keys backed by swtpm — plus negative tests (corrupted block, modified file, wrong key) and a written architecture document with a recovery procedure.
What you leave with
- Hands-on dm-verity image creation, booting and corruption testing
- A working IMA/EVM policy you wrote and can defend
- Key-management fluency: keyrings, trusted keys and TPM backing
- A complete integrity architecture with evidence and a recovery plan
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 18 Oct – 20 Oct 20263 full days | RiyadhIn person · KAFD Conference Centre | 4 of 14 | — | SAR 9,000 | |
| 25 Oct – 27 Oct 20263 full days | Kuwait CityIn person · Al Hamra Tower | 9 of 14 | — | KWD 740 | |
| 1 Nov – 3 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 4 of 14 | — | OMR 920 | |
| 1 Nov – 8 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 8 of 20 | — | US$1,750 | |
| 2 Nov – 4 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 9 of 14 | — | CAD 3,260 | |
| 9 Nov – 11 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 4 of 14 | CAD 2,930until 10 Oct | ||
| 9 Nov – 16 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 13 of 20 | US$1,580until 10 Oct | ||
| 16 Nov – 18 Nov 20263 full days | LondonIn person · Shoreditch Works | 9 of 14 | GBP 1,680until 17 Oct | ||
| 16 Nov – 23 Nov 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 18 of 20 | US$1,580until 17 Oct | ||
| 23 Nov – 25 Nov 20263 full days | BerlinIn person · Factory Görlitzer Park | 4 of 14 | EUR 1,990until 24 Oct |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.