SEC-320 · Kernel Security · Advanced

Integrity: IMA/EVM & dm-verity — full syllabus

Measuring and verifying what runs on the system, from block device to individual file.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Embedded and platform engineers building systems that must prove what they are running — from the block device up to individual files.

Prerequisites

Course outline

Day 1 — dm-verity

  • Merkle-tree verification of read-only filesystems: layout, hash tree and root hash
  • Creating verity images with veritysetup; booting them from initramfs
  • Error handling: what happens on corruption and how to test it
  • Root-hash distribution: where the trust anchor lives (cmdline, TPM, signed image)
  • dm-verity with forward error correction for flash-level bit rot

Day 2 — IMA and EVM

  • IMA measurement: what gets hashed and where the measurement list lives
  • IMA appraisal: enforcing signatures on file access, and its failure modes
  • IMA policy: writing measurement and appraisal rules for a real rootfs
  • EVM: protecting extended attributes against offline modification
  • Key management: kernel keyrings, trusted and encrypted keys, and TPM-backed options

Day 3 — The verified boot-to-runtime chain

  • Chain of trust from boot ROM to kernel: what each link must prove
  • Measured boot vs verified boot, and where the TPM fits (swtpm for the labs)
  • Assembling dm-verity plus IMA/EVM into one coherent architecture
  • Update and recovery: keeping the chain intact across A/B updates
  • Writing the integrity architecture document an assessor will ask for

Hands-on labs

  1. Lab: Build a dm-verity image, boot it in QEMU, corrupt a block and observe the failure behaviour
  2. Lab: Change the root hash and prove the system refuses to boot — then restore it
  3. Lab: Write an IMA policy, boot with it and inspect the measurement list after exercising the system
  4. Lab: Enable IMA appraisal on a test rootfs and show that a modified file is refused
  5. Lab: Seal a trusted key against a swtpm and use it in the EVM setup

Capstone project

Assemble and demonstrate a verified boot-to-runtime chain in QEMU: a dm-verity rootfs anchored to a known root hash, IMA measurement and appraisal policy on top, EVM protecting the attributes, and trusted keys backed by swtpm — plus negative tests (corrupted block, modified file, wrong key) and a written architecture document with a recovery procedure.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 20 Oct 20263 full days RiyadhIn person · KAFD Conference Centre 4 of 14 —SAR 9,000
25 Oct – 27 Oct 20263 full days Kuwait CityIn person · Al Hamra Tower 9 of 14 —KWD 740
1 Nov – 3 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 4 of 14 —OMR 920
1 Nov – 8 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 8 of 20 —US$1,750
2 Nov – 4 Nov 20263 full days OttawaIn person · Kanata North Tech Park 9 of 14 —CAD 3,260
9 Nov – 11 Nov 20263 full days TorontoIn person · MaRS Discovery District 4 of 14 CAD 2,930until 10 OctCAD 3,260
9 Nov – 16 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 13 of 20 US$1,580until 10 OctUS$1,750
16 Nov – 18 Nov 20263 full days LondonIn person · Shoreditch Works 9 of 14 GBP 1,680until 17 OctGBP 1,870
16 Nov – 23 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 18 of 20 US$1,580until 17 OctUS$1,750
23 Nov – 25 Nov 20263 full days BerlinIn person · Factory Görlitzer Park 4 of 14 EUR 1,990until 24 OctEUR 2,210

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.