Menu

Home

Dmitry Kasatkin mzohar

The goals of the kernel integrity subsystem are to detect if files have been accidentally or maliciously altered, both remotely and locally, appraise a file's measurement against a "good" value stored as an extended attribute, and enforce local file integrity. These goals are complementary to Mandatory Access Control(MAC) protections provided by LSM modules, such as SElinux and Smack, which, depending on policy, can attempt to protect file integrity.

Overview

Features

The following modules provide serveral integrity functions:

  • Collect – measure a file before it is accessed.
  • Store – add the measurement to a kernel resident list and, if a
    hardware Trusted Platform Module (TPM) is present, extend the IMA
    PCR
  • Attest – if present, use the TPM to sign the IMA PCR value, to
    allow a remote validation of the measurement list.
  • Appraise – enforce local validation of a measurement against a
    “good” value stored in an extended attribute of the file.
  • Protect – protect a file's security extended attributes
    (including appraisal hash) against off-line attack.

  • Audit – audit the file hashes.

The first three functions were introduced with Integrity Measurement Architecture (IMA) in 2.6.30. The "appraise" and "protect" features were originally posted as a single EVM/IMA-appraisal patch set for in the 2.6.36 timeframe, but were subsequently split. EVM, the "protect" feature, was upstreamed in Linux 3.2, using a simplier and more secure method for loading the 'evm-key', based on the new Kernel Key Retention Trusted and Encrypted keys. EVM support for protecting file metadata based on digital signatures was upstreamed in the Linux 3.3. IMA-appraisal, the fourth aspect, appraising a file's integrity, was upstreamed in Linux 3.7.

The goals, design, and benefits of these features are further described in the whitepaper "An Overview of the Linux Integrity Subsystem".

Components

IMA-measurement, one component of the kernel's integrity subsystem, is part of an overall Integrity Architecture based on the Trusted Computing Group's open standards, including Trusted Platform Module (TPM), Trusted Boot, Trusted Software Stack (TSS), Trusted Network Connect (TNC), and Platform Trust Services (PTS). The linux-ima project page contains a diagram showing how these standards relate, and provides links to the respective specifications and open source implementations. IMA-measurement and EVM can still run on platforms without a hardware TPM, although without the hardware guarantee of compromise detection.

IMA-appraisal, a second component of the kernel's integrity subsystem, extends the "secure boot" concept of verifying a file's integrity, before transferring control or allowing the file to be accessed by the OS.

IMA-audit, another component of the kernel's integrity subsystem, includes file hashes in the system audit logs, which can be used to augment existing system security analytics/forensics.

The IMA-measurement, IMA-appraisal, and IMA-audit aspects of the kernel's integrity subsystem complement each other, but can be configured and used independently of each other.

Integrity Measurement Architecture (IMA-measurement)

IMA-measurement is an open source trusted computing component. IMA maintains a runtime measurement list and, if anchored in a hardware Trusted Platform Module(TPM), an aggregate integrity value over this list. The benefit of anchoring the aggregate integrity value in the TPM is that the measurement list cannot be compromised by any software attack, without being detectable. Hence, on a trusted boot system, IMA-measurement can be used to attest to the system's runtime integrity.

Enabling IMA-measurement

IMA was first included in the 2.6.30 kernel. For distros that enable IMA by default in their kernels, collecting IMA measurements simply requires rebooting the kernel with a builtin "ima_policy=" on the boot command line. (Fedora/RHEL may also require the boot command line parameter 'ima=on'.)

To determine if your distro enables IMA by default, mount securityfs (mount -t securityfs security /sys/kernel/security), if it isn't already mounted, and then check if '<securityfs>/integrity/ima' exists. If it exists, IMA is indeed enabled. On systems without IMA enabled, recompile the kernel with the config option 'CONFIG_IMA' enabled.</securityfs>

Controlling IMA-measurement

IMA is controlled with several kernel command line parameters:

ima_audit= informational audit logging
Format: { "0" | "1" }
0 -- normal integrity auditing messages. (Default)
1 -- enable additional informational integrity auditing messages.

(eg. Although file measurements are only added to the measurement list once and cached, if the inode is flushed, subsequent access to the inode will result in re-measuring the file and attempting to add the measurement again to the measurement list. Enabling ima_audit will log such attempts.)

ima_policy= builtin policy
Format: {"tcb" | "appraise_tcb" | "secure-boot"}
NEW Linux-4.13 default: no policy

ima_template= template used
Format: { "ima" | "ima-ng" | "ima-sig" }
Linux 3.13 default: "ima-ng"

ima_hash= hash used
Format: { "sha1" | "md5" | "sha256" | "sha512" | "wp512" | ... }
'ima' template default: "sha1"
Linux 3.13 default: "sha256"

ima_tcb (deprecated)
If specified, enables the TCB policy, which meets the needs of the Trusted Computing Base. This means IMA will measure all programs exec'd, files mmap'd for exec, and all files opened for read by uid=0.

IMA Measurement List

IMA-measurements maintains a runtime measurement list, which can be displayed as shown below.

  • mount securityfs as /sys/kernel/security

    $ su -c 'mkdir /sys/kernel/security'
    $ su -c 'mount -t securityfs securityfs /sys/kernel/security'

Modify /etc/fstab to mount securityfs on boot.

  • display the runtime measurement list (Only root is allowed access to securityfs files.)

Example 1: 'ima-ng' template
$ su -c 'head -5 /sys/kernel/security/ima/ascii_runtime_measurements'

PCR     template-hash                           filedata-hash                           filename-hint
10 91f34b5c671d73504b274a919661cf80dab1e127 ima-ng sha1:1801e1be3e65ef1eaa5c16617bec8f1274eaf6b3 boot_aggregate 
10 8b1683287f61f96e5448f40bdef6df32be86486a ima-ng sha256:efdd249edec97caf9328a4a01baa99b7d660d1afc2e118b69137081c9b689954 /init 
10 ed893b1a0bc54ea5cd57014ca0a0f087ce71e4af ima-ng sha256:1fd312aa6e6417a4d8dcdb2693693c81892b3db1a6a449dec8e64e4736a6a524 /usr/lib64/ld-2.16.so
10 9051e8eb6a07a2b10298f4dc2342671854ca432b ima-ng sha256:3d3553312ab91bb95ae7a1620fedcc69793296bdae4e987abc5f8b121efd84b8 /etc/ld.so.cache

PCR: default CONFIG_IMA_MEASURE_PCR_IDX is 10
template-hash: sha1 hash(filedata-hash length, filedata-hash, pathname length, pathname)
filedata-hash: sha256 hash(filedata)

Example 2: 'ima-sig' template (same format as ima-ng, but with an appended signature when present)

PCR     template-hash                           filedata-hash                           filename-hint                         file-signature
10 f63c10947347c71ff205ebfde5971009af27b0ba ima-sig sha256:6c118980083bccd259f069c2b3c3f3a2f5302d17a685409786564f4cf05b3939 /usr/lib64/libgspell-1.so.1.0.0   0302046e6c10460100aa43a4b1136f45735669632ad ...
10 595eb9bf805874b459ce073af158378f274ea961 ima-sig sha256:8632769297867a80a9614caa98034d992441e723f0b383ca529faa306c640638 /usr/lib64/gedit/plugins/libmodelines.so 0302046e6c104601002394b70ab93 ...

Example 3: original 'ima' template

PCR     template-hash                           filedata-hash                           filename-hint
10 7971593a7ad22a7cce5b234e4bc5d71b04696af4 ima b5a166c10d153b7cc3e5b4f1eab1f71672b7c524 boot_aggregate
10 2c7020ad8cab6b7419e4973171cb704bdbf52f77 ima e09e048c48301268ff38645f4c006137e42951d0 /init
10 ef7a0aff83dd46603ebd13d1d789445365adb3b3 ima 0f8b3432535d5eab912ad3ba744507e35e3617c1 /init
10 247dba6fc82b346803660382d1973c019243e59f ima 747acb096b906392a62734916e0bb39cef540931 ld-2.9.so
10 341de30a46fa55976b26e55e0e19ad22b5712dcb ima 326045fc3d74d8c8b23ac8ec0a4d03fdacd9618a ld.so.cache

PCR: default CONFIG_IMA_MEASURE_PCR_IDX is 10
template-hash: sha1 hash(filedata-hash, filename-hint)
filedata-hash: sha1 hash(filedata)

The first element in the runtime measurement list, shown above, is the boot_aggregate. The boot_aggregate is a SHA1 hash over tpm registers 0-7, assuming a TPM chip exists, and zeroes, if the TPM chip does not exist.

  • display the bios measurement list entries, used in calculating the boot aggregate

    $ su -c 'head /sys/kernel/security/tpm0/ascii_bios_measurements'

    0 f797cb88c4b07745a129f35ea01b47c6c309cda9 08 [S-CRTM Version]
    0 dca68da0707a9a52b24db82def84f26fa463b44d 01 [POST CODE]
    0 dd9efa31c88f467c3d21d3b28de4c53b8d55f3bc 01 [POST CODE]
    0 dd261ca7511a7daf9e16cb572318e8e5fbd22963 01 [POST CODE]
    0 df22cabc0e09aabf938bcb8ff76853dbcaae670d 01 [POST CODE]
    0 a0d023a7f94efcdbc8bb95ab415d839bdfd73e9e 01 [POST CODE]
    0 38dd128dc93ff91df1291a1c9008dcf251a0ef39 01 [POST CODE]
    0 dd261ca7511a7daf9e16cb572318e8e5fbd22963 01 [POST CODE]
    0 df22cabc0e09aabf938bcb8ff76853dbcaae670d 01 [POST CODE]
    0 a0d023a7f94efcdbc8bb95ab415d839bdfd73e9e 01 [POST CODE]

Verifying IMA Measurements

The IMA tests programs are part of the Linux Test Project.

  • Download, compile, and install the standalone version of the IMA LTP test programs in /usr/local/bin.

    $ wget -O ltp-ima-standalone-v2.tar.gz http://downloads.sf.net/project/linux-ima/linux-ima/ltp-ima-standalone-v2.tar.gz
    $ tar -xvzf ltp-ima-standalone-v2.tar.gz
    ima-tests/Makefile
    ima-tests/README
    ima-tests/ima_boot_aggregate.c
    ima-tests/ima_measure.c
    ima-tests/ima_mmap.c
    ima-tests/ima_sigv2.c
    ima-tests/ltp-tst-replacement.c
    ima-tests/pkeys.c
    ima-tests/rsa_oid.c
    ima-tests/config.h
    ima-tests/debug.h
    ima-tests/hash_info.h
    ima-tests/ima_sigv2.h
    ima-tests/list.h
    ima-tests/pkeys.h
    ima-tests/rsa.h
    ima-tests/test.h
    $ cd ima-tests
    $ make
    $ su -c 'make install'

  • ima_boot_aggregate <tpm_bios file=""></tpm_bios>

Using the TPM's binary bios measurement list, re-calculate the boot aggregate.

$ su -c '/usr/local/bin/ima_boot_aggregate /sys/kernel/security/tpm0/binary_bios_measurements'
000 f797cb88c4b07745a129f35ea01b47c6c309cda9
000 dca68da0707a9a52b24db82def84f26fa463b44d
< snip >
005 6895eb784cdaf843eaad522e639f75d24d4c1ff5
PCR-00: 07274edf7147abda49200100fd668ce2c3a374d7
PCR-01: 48dff4fbf3a34d56a08dfc1504a3a9d707678ff7
PCR-02: 53de584dcef03f6a7dac1a240a835893896f218d
PCR-03: 3a3f780f11a4b49969fcaa80cd6e3957c33b2275
PCR-04: acb44e9dd4594d3f121df2848f572e4d891f0574
PCR-05: df72e880e68a2b52e6b6738bb4244b932e0f1c76
PCR-06: 585e579e48997fee8efd20830c6a841eb353c628
PCR-07: 3a3f780f11a4b49969fcaa80cd6e3957c33b2275
boot_aggregate:b5a166c10d153b7cc3e5b4f1eab1f71672b7c524

and compare the value with the ascii_runtime_measurement list value.

$ su -c 'cat /sys/kernel/security/ima/ascii_runtime_measurements | grep boot_aggregate'
10 7971593a7ad22a7cce5b234e4bc5d71b04696af4 ima b5a166c10d153b7cc3e5b4f1eab1f71672b7c524 boot_aggregate


  • ima_measure <binary_runtime_measurements> [--validate] [--verify] [--verbose]</binary_runtime_measurements>

using the IMA binary measurement list, calculate the PCR aggregate value

$ su -c '/usr/local/bin/ima_measure /sys/kernel/security/ima/binary_runtime_measurements --validate'
PCRAggr (re-calculated): B4 D1 93 D8 FB 31 B4 DD 36 5D DA AD C1 51 AC 84 FA 88 78 1B

and compare it against the PCR value

$ cat /sys/devices/pnp0/00:0a/pcrs | grep PCR-10
PCR-10: B4 D1 93 D8 FB 31 B4 DD 36 5D DA AD C1 51 AC 84 FA 88 78 1B

IMA re-measuring files

Part of the TCG requirement is that all Trusted Computing Base (TCB) files be measured, and re-measured if the file has changed, before reading/executing the file. IMA detects file changes based on i_version. To re-measure a file after it has changed, the filesystem must support i_version and, if needed, be mounted with i_version (eg. ext3, ext4). Not all filesystems require the explicit mount option. With commit a2a2c3c8580a ("ima: Use i_version only when filesystem supports it") i_version is considered an optimization. If i_version is not enabled, either because the local filesystem does not support it or the filesystem was not mounted with i_version, the file will now always be re-measured, whether or not the file changed, but only new measurements will be added to the measurement list.

  • Attempt to mount a filesystem with i_version support.

    $ su -c 'mount -o remount,rw,iversion /home'
    
    mount: you must specify the filesystem type
    

    Attempt to remount '/home' with i_version support, shown above, failed. Please install a version of the util-linux-ng-2.15-rc1 package or later.

  • To automatically mount a filesystem with i_version support, update /etc/fstab.

    UUID=blah  /home                   ext3    defaults,iversion
    
  • Mount the root filesystem with i_version.

    • For systems with /etc/rc.sysinit, update the mount options
      adding 'iversion':

      # Remount the root filesystem read-write.
      update_boot_stage RCmountfs
      if remount_needed ; then
        action $"Remounting root filesystem in read-write mode: " mount -n -o remount,rw,iversion /
      fi
      
    • For systems using dracut, root 'mount' options can be specified on the boot
      command line using 'rootflags'. Add 'rootflags=i_version'. Unlike 'mount',
      which expects 'iversion', notice that on the boot command line 'i_version'
      contains an underscore.

Linux-audit support

As of Linux-audit 2.0, support for integrity auditing messages is available.

Defining an LSM specific policy

The ima_tcb default measurement policy in linux-2.6.30 measures all system sensitive files - executables, mmapped libraries, and files opened for read by root. These measurements, the measurement list and the aggregate integrity value, can be used to attest to a system's
runtime integrity. Based on these measurements, a remote party can detect whether critical system files have been modified or if malicious software has been executed.

Default policy

dont_measure fsmagic=PROC_SUPER_MAGIC
dont_measure fsmagic=SYSFS_MAGIC
dont_measure fsmagic=DEBUGFS_MAGIC
dont_measure fsmagic=TMPFS_MAGIC
dont_measure fsmagic=SECURITYFS_MAGIC
dont_measure fsmagic=SELINUX_MAGIC
measure func=BPRM_CHECK
measure func=FILE_MMAP mask=MAY_EXEC

< add LSM specific rules here >

measure func=PATH_CHECK mask=MAY_READ uid=0

But not all files opened by root for read, are necessarily part of the Trusted Computing Base (TCB), and therefore do not need to be measured. Linux Security Modules (LSM) maintain file metadata, which can be leveraged to limit the number of files measured.

Examples: adding LSM specific rules

SELinux:
dont_measure obj_type=var_log_t
dont_measure obj_type=auditd_log_t

Smack:
measure subj_user=_ func=INODE_PERM mask=MAY_READ

To replace the default policy 'cat' the custom IMA measurement policy and redirect the output to "< securityfs >/ima/policy". Both dracut and systemd have been modified to load the custom IMA policy. If the IMA policy contains LSM labels, then the LSM policy must be loaded prior to the IMA policy. (eg. if systemd loads the SELinux policy, then systemd must also load the IMA policy.)

systemd commit c8161158 adds support for loading a custom IMA measurement policy. Simply place the custom IMA policy in /etc/ima/ima-policy. systemd will automatically load the custom policy.

dracut commit 0c71fb6 add initramfs support for loading the custom IMA measurement policy. Build and install dracut (git://git.kernel.org/pub/scm/boot/dracut/dracut.git), to load the custom IMA measurement policy(default: /etc/sysconfig/ima-policy).

For more information on defining an LSM specific measurement/appraisal/audit policy, refer to the kernel Documentation/ABI/testing/ima_policy.

IMA-appraisal

IMA currently maintains an integrity measurement list used for remote attestation. The IMA-appraisal extension adds local integrity validation and enforcement of the measurement against a "good" value stored as an extended attribute 'security.ima'. The inital method for validating 'security.ima' are hashed based, which provides file data integrity, and digital signature based, which in addition to providing file data integrity, provides authenticity.

Enabling IMA-appraisal

IMA-appraisal was upstreamed in Linux 3.7. For distros that enable IMA-appraisal by default in their kernels, appraising file measurements requires rebooting the kernel first with the boot command line parameters 'ima_appraise_tcb' and ima_appraise='fix' to label the filesystem. Once labeled, reboot with just the 'ima_appraise_tcb' boot command line parameter.

Refer to compiling the kernel for directions on configuring and building a new kernel with IMA-appraisal support enabled.

Understanding the IMA-appraisal policy

The IMA-appraisal policy extends the measurement policy ABI with two new keywords: appraise/dont_appraise. The default appraise policy appraises all files owned by root. Like the default measurement policy, the default appraisal policy does not appraise pseudo filesystem files (eg. debugfs, tmpfs, securityfs, or selinuxfs.)

Additional rules can be added to the default IMA measurement/appraisal policy, which take advantage of the SELinux labels, for a more fine grained policy. Refer to Documentation/ABI/testing/ima_policy.

Labeling the filesystem with 'security.ima' extended attributes

A new boot parameter 'ima_appraise=' has been defined in order to label existing file systems with the 'security.ima' extended attribute.

  • ima_appraise= appraise integrity measurements\
    Format: { "off" | "log" | "fix" } \

off - is a runtime parameter that turns off integrity appraisal verification.
enforce - verifies and enforces runtime file integrity. [default]
fix - for non-digitally signed files, updates the 'security.ima' xattr to reflect the existing file hash.

After building a kernel with IMA-appraisal enabled and verified that the filesystems are mounted with i_version support, to label the filesystem, reboot with the boot command line options 'ima_appraise_tcb' and 'ima_appraise=fix'. Opening a file owned by root, will cause the 'security.ima' extended attributes to be written. For example, to label the entire filesystem, execute:

find / \\( -fstype rootfs -o ext4 -type f \\) -uid 0 -exec head -n 1 '{}' >/dev/null \\;

Labeling 'immutable' files with digital signatures

'Immutable' files, such as ELF executables, can be digitally signed, storing the digital signature in the 'security.ima' xattr. Creating the digital signature requires generating an RSA private/public key pair. The private key is used to sign the file, while the public key is used to verify the signature. For example, to digitally sign all kernel modules, replace <rsa private="" key="">, below, with the pathname to your RSA private key, and execute:</rsa>

find /lib/modules -name "\*.ko" -type f -uid 0 -exec evmctl sign --imasig '{}' <RSA private key> \;

evmctl manual page is here evmctl.1.html

Running with IMA-appraisal

Once the filesystem has been properly labeled, before rebooting, re-install the new labeled kernel. Modify the initramfs to load the RSA public key on the IMA keyring, using evmctl. Reboot with the 'ima_appraise_tcb' and, possibly, the 'rootflags=i_version' options.

Extending trusted and secure boot to the OS

( Place holder )

Including file signatures in the measurement list

The 'ima-sig' template, in addition to the file data hash and the full pathname, includes the file signature, as stored in the 'security.ima' extended attribute.

10 d27747646f317e3ca1205287d0615073fe676bc6 ima-