SEC-320 · Kernel Security

Integrity: IMA/EVM & dm-verity

Measuring and verifying what runs on the system, from block device to individual file.

Advanced 3 days in person6 half-days online Max 14 in person

Who this course is for

Embedded and platform engineers building systems that must prove what they are running — from the block device up to individual files.

Prerequisites

Kernel build and boot experience (QEMU acceptable)Basic public-key cryptography conceptsBlock-device and initramfs familiarity

Course outline

Day 1 — dm-verity

  • Merkle-tree verification of read-only filesystems: layout, hash tree and root hash
  • Creating verity images with veritysetup; booting them from initramfs
  • Error handling: what happens on corruption and how to test it
  • Root-hash distribution: where the trust anchor lives (cmdline, TPM, signed image)
  • dm-verity with forward error correction for flash-level bit rot

Day 2 — IMA and EVM

  • IMA measurement: what gets hashed and where the measurement list lives
  • IMA appraisal: enforcing signatures on file access, and its failure modes
  • IMA policy: writing measurement and appraisal rules for a real rootfs
  • EVM: protecting extended attributes against offline modification
  • Key management: kernel keyrings, trusted and encrypted keys, and TPM-backed options

Day 3 — The verified boot-to-runtime chain

  • Chain of trust from boot ROM to kernel: what each link must prove
  • Measured boot vs verified boot, and where the TPM fits (swtpm for the labs)
  • Assembling dm-verity plus IMA/EVM into one coherent architecture
  • Update and recovery: keeping the chain intact across A/B updates
  • Writing the integrity architecture document an assessor will ask for

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Build a dm-verity image, boot it in QEMU, corrupt a block and observe the failure behaviour
  2. Lab: Change the root hash and prove the system refuses to boot — then restore it
  3. Lab: Write an IMA policy, boot with it and inspect the measurement list after exercising the system
  4. Lab: Enable IMA appraisal on a test rootfs and show that a modified file is refused
  5. Lab: Seal a trusted key against a swtpm and use it in the EVM setup

Capstone project

Assemble and demonstrate a verified boot-to-runtime chain in QEMU: a dm-verity rootfs anchored to a known root hash, IMA measurement and appraisal policy on top, EVM protecting the attributes, and trusted keys backed by swtpm — plus negative tests (corrupted block, modified file, wrong key) and a written architecture document with a recovery procedure.

What you leave with

  • Hands-on dm-verity image creation, booting and corruption testing
  • A working IMA/EVM policy you wrote and can defend
  • Key-management fluency: keyrings, trusted keys and TPM backing
  • A complete integrity architecture with evidence and a recovery plan

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Embedded and platform engineers building systems that must prove what they are running — from the block device up to individual files. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: Kernel build and boot experience (QEMU acceptable); Basic public-key cryptography concepts; Block-device and initramfs familiarity. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 20 Oct 20263 full days RiyadhIn person · KAFD Conference Centre 4 of 14 —SAR 9,000
25 Oct – 27 Oct 20263 full days Kuwait CityIn person · Al Hamra Tower 9 of 14 —KWD 740
1 Nov – 3 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 4 of 14 —OMR 920
1 Nov – 8 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 8 of 20 —US$1,750
2 Nov – 4 Nov 20263 full days OttawaIn person · Kanata North Tech Park 9 of 14 —CAD 3,260
9 Nov – 11 Nov 20263 full days TorontoIn person · MaRS Discovery District 4 of 14 CAD 2,930until 10 OctCAD 3,260
9 Nov – 16 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 13 of 20 US$1,580until 10 OctUS$1,750
16 Nov – 18 Nov 20263 full days LondonIn person · Shoreditch Works 9 of 14 GBP 1,680until 17 OctGBP 1,870
16 Nov – 23 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 18 of 20 US$1,580until 17 OctUS$1,750
23 Nov – 25 Nov 20263 full days BerlinIn person · Factory Görlitzer Park 4 of 14 EUR 1,990until 24 OctEUR 2,210

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov