Hardening Features Taxonomy Roadmap¶
Complete mapping table for all 44 hands-on Linux kernel security hardening features across 11 core categories.
1. Feature Categories Hierarchy¶
mindmap
root((Linux Kernel Hardening))
01. Stack and Buffer
Stack Canary
FORTIFY_SOURCE
Shadow Call Stack
Stackleak
02. Memory Layout
KASLR
FG-KASLR
Randomize Memory
03. Memory Permissions
Strict RWX
SMEP and PXN
SMAP and PAN
Page Table Check
KPTI
04. Control Flow Integrity
Clang kCFI
Intel CET IBT and Shstk
ARM PAC and BTI
05. Heap and SLAB
Freelist Random
Freelist Hardened
Init on Alloc
Hardened Usercopy
KFENCE
06. Structure and Compiler
Structleak
Randstruct
07. Speculative Execution
Spectre v1
Spectre v2 Retpoline
SSBD
MDS and TAA
08. MAC and LSM
LSM Stacking
AppArmor
SELinux
Landlock
09. Integrity Verification
IMA
EVM
IPE
Lockdown
Module Signature
10. Attack Surface Reduction
Seccomp-BPF
BPF Hardening
Strict Devmem
Kernel Info Leaks
Yama Ptrace Scope
Kexec Restrictions
11. Modern ARMv8/ARMv9
ARM64 MTE
ARMv9 POE
Android AVF and pKVM
Arm CCA
2. Feature Lab Status (All 44 Features)¶
Category 01. Stack & Buffer Protection¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 01 | Stack Protector (Canary) | CONFIG_STACKPROTECTOR_STRONG |
x86_64, arm64 | Ready |
| 02 | FORTIFY_SOURCE | CONFIG_FORTIFY_SOURCE |
x86_64, arm64 | Ready |
| 03 | Shadow Call Stack (SCS) | CONFIG_SHADOW_CALL_STACK |
arm64 | Ready |
| 04 | STACKLEAK Plugin | CONFIG_GCC_PLUGIN_STACKLEAK |
x86_64, arm64 | Ready |
Category 02. Memory Layout & Randomization¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 05 | KASLR | CONFIG_RANDOMIZE_BASE |
x86_64, arm64 | Ready |
| 06 | FG-KASLR | CONFIG_FG_KASLR |
x86_64 | Ready |
| 07 | Randomize Memory | CONFIG_RANDOMIZE_MEMORY |
x86_64, arm64 | Ready |
Category 03. Memory Permissions & Access Separation¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 08 | Strict Kernel RWX (W^X) | CONFIG_STRICT_KERNEL_RWX |
x86_64, arm64 | Ready |
| 09 | SMEP & PXN (ret2usr Defense) | CPU Feature (SMEP / PXN) | x86_64, arm64 | Ready |
| 10 | SMAP & PAN (User Data Access Prevention) | CPU Feature (SMAP / PAN) | x86_64, arm64 | Ready |
| 11 | Page Table Check | CONFIG_PAGE_TABLE_CHECK |
x86_64, arm64 | Ready |
| 12 | KPTI (Kernel Page Table Isolation) | CONFIG_PAGE_TABLE_ISOLATION |
x86_64, arm64 | Ready |
Category 04. Control Flow Integrity (CFI)¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 13 | Clang kCFI | CONFIG_CFI_CLANG |
x86_64, arm64 | Ready |
| 14 | x86 IBT & Shadow Stack (CET) | CONFIG_X86_KERNEL_IBT |
x86_64 | Ready |
| 15 | ARM64 BTI & PAC | CONFIG_ARM64_BTI, CONFIG_ARM64_PTR_AUTH |
arm64 | Ready |
Category 05. Heap & SLAB Allocator Hardening¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 16 | SLAB Freelist Hardening | CONFIG_SLAB_FREELIST_HARDENED |
x86_64, arm64 | Ready |
| 17 | Heap Zeroing (Alloc & Free) | CONFIG_INIT_ON_ALLOC_DEFAULT_ON |
x86_64, arm64 | Ready |
| 18 | Hardened Usercopy | CONFIG_HARDENED_USERCOPY |
x86_64, arm64 | Ready |
| 19 | KFENCE (Memory Safety Detector) | CONFIG_KFENCE |
x86_64, arm64 | Ready |
Category 06. Structure & Compiler Level Protections¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 20 | Structleak Plugin | CONFIG_GCC_PLUGIN_STRUCTLEAK_BYREF_ALL |
x86_64, arm64 | Ready |
| 21 | Randstruct Plugin | CONFIG_RANDSTRUCT_FULL |
x86_64, arm64 | Ready |
Category 07. Speculative Execution Defenses¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 22 | Spectre v1 (array_index_nospec) | array_index_nospec |
x86_64, arm64 | Ready |
| 23 | Spectre v2 (Retpoline, IBPB, STIBP) | CONFIG_MITIGATION_RETPOLINE |
x86_64, arm64 | Ready |
| 24 | Speculative Store Bypass Disable (SSBD) | CONFIG_MITIGATION_SSB |
x86_64, arm64 | Ready |
| 25 | MDS & TAA Mitigation (VERW) | CONFIG_MITIGATION_MDS |
x86_64 | Ready |
Category 08. Mandatory Access Control & LSM Framework¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 26 | Stackable LSM Architecture | CONFIG_LSM |
x86_64, arm64 | Ready |
| 27 | AppArmor Process Isolation | CONFIG_SECURITY_APPARMOR |
x86_64, arm64 | Ready |
| 28 | SELinux Type Enforcement | CONFIG_SECURITY_SELINUX |
x86_64, arm64 | Ready |
| 29 | Landlock Sandboxing | CONFIG_SECURITY_LANDLOCK |
x86_64, arm64 | Ready |
Category 09. System & Binary Integrity Verification¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 30 | IMA Integrity Measurement | CONFIG_IMA |
x86_64, arm64 | Ready |
| 31 | EVM Metadata Protection | CONFIG_EVM |
x86_64, arm64 | Ready |
| 32 | IPE Policy Enforcement | CONFIG_SECURITY_IPE |
x86_64, arm64 | Ready |
| 33 | Kernel Lockdown LSM | CONFIG_SECURITY_LOCKDOWN_LSM |
x86_64, arm64 | Ready |
| 34 | Module Signature Verification | CONFIG_MODULE_SIG_FORCE |
x86_64, arm64 | Ready |
Category 10. Attack Surface Reduction & System Hardening¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 35 | Seccomp-BPF Syscall Filtering | CONFIG_SECCOMP_FILTER |
x86_64, arm64 | Ready |
| 36 | BPF Hardening & JIT Blinding | CONFIG_BPF_JIT_ALWAYS_ON |
x86_64, arm64 | Ready |
| 37 | Strict Devmem & Strict I/O | CONFIG_STRICT_DEVMEM |
x86_64, arm64 | Ready |
| 38 | Kernel Info Leaks & Dmesg Restrict | CONFIG_SECURITY_DMESG_RESTRICT |
x86_64, arm64 | Ready |
| 39 | Yama LSM Ptrace Scope | CONFIG_SECURITY_YAMA |
x86_64, arm64 | Ready |
| 40 | Kexec Restrictions & Hardening | CONFIG_KEXEC_SIG_FORCE |
x86_64, arm64 | Ready |
Category 11. Modern ARMv8/ARMv9 & Mobile Security¶
| # | Feature Name | Kconfig Symbol | Supported Arch | Status |
|---|---|---|---|---|
| 41 | ARM64 MTE (Memory Tagging Extension) | CONFIG_ARM64_MTE |
arm64 | Ready |
| 42 | ARMv9 POE / S1POE (Permission Overlay) | CONFIG_ARM64_POE |
arm64 | Ready |
| 43 | Android Virtualization (AVF / pKVM) | CONFIG_KVM |
arm64 | Ready |
| 44 | Arm CCA (Confidential Compute Architecture) | CONFIG_ARM64_RME |
arm64 | Ready |