ENGLISH

The Embedded Linux Security Handbook: Fortify your embedded Linux systems from design to deployment

Book information

Publisher
Packt
Year
2025
ISBN
9781835885642
Language
english
Format
PDF
Filesize
26 MB (26984996 bytes)
Edition
1
Pages
278\278
Time added
2025-04-22 17:25:30

Description

Written by Linux and open-source expert Matt St. Onge, this definitive guide helps you build and secure Linux-based appliances capable of withstanding the latest cyber threats "In the face of growing cybersecurity threats, this book by Matt St. Onge fills a critical gap by providing a comprehensive guide to Linux security tailored for those who build and maintain embedded Linux systems or appliances."- Rama Krishnan, Senior Director of Engineering, Veritas Technologies All formats include a free PDF and an invitation to the Embedded System Professionals community Book Description As embedded Linux systems power countless devices in our daily lives, they’ve become prime targets for cyberattacks. In this in-depth guide to safeguarding your Linux devices, the author leverages his 30+ years of technology experience to help you mitigate the risks associated with hardware and software vulnerabilities. This book introduces you to the world of embedded systems, the brains behind your everyday appliances. It takes you through the different types of embedded systems, their uses, and the platforms they run on while addressing their unique security challenges and support considerations. You’ll learn to build a successful, secure, and user-friendly solution by exploring the critical hardware and software components that form the foundation of a secure appliance. We won't forget the human element either; you'll find out how to configure your system to prevent user errors and maintain its integrity. The book lets you put your newfound knowledge into action, guiding you through designing a robust build chain that supports the entire life cycle of your appliance solution, enabling seamless updates without your direct involvement. By the end of this book, you’ll be able to adapt your appliance to the ever-evolving threat landscape, ensuring its continued security and functionality in real-world conditions. What you will learn Understand how to determine the optimal hardware platform based on design criteria Recognize the importance of security by design in embedded systems Implement advanced security measures such as TPM, LUKS encryption, and secure boot processes Discover best practices for secure life cycle management, including appliance update and upgrade mechanisms Create a secure software supply chain efficiently Implement childproofing by controlling access and resources on the appliance Who this book is for This book helps embedded systems professionals, embedded software engineers, and Linux security professionals gain the skills needed to address critical security requirements during the design, development, and testing of software for embedded systems. If you’re a product manager or architect, this book will teach you how to identify and integrate essential security features based on the specific platforms and their intended users. Cover Title page Copyright and credits Dedication Foreword Author’s Note Contributors Table of Contents Preface Part 1:Introduction to Embedded Systems and Secure Design 1 Chapter 1: Welcome to the Cyber Security Landscape What is a Linux-embedded system? How are Linux-embedded systems used? Why is securing Linux-embedded systems so important? Examples where embedded Linux systems had a security breach Summary 2 Chapter 2: Security Starts at the Design Table What are the business needs that the solution caters to? Who is my target buyer and my target user? The target buyer The target user Will any specific government compliance standards drive the decision tree? Healthcare systems (and data privacy) Financial services systems Retail and online marketplace systems Government and military systems How will we support this appliance solution? Managed service Online support Offline support No support/self-support Replacements Other product-impacting needs and concerns Hardware life cycle Linux distribution life cycle Supply chain issues Summary 3 Chapter 3: Applying Design Requirements Criteria – Hardware Selection What are the targeted performance requirements? Virtual appliances T-shirt sizing CPU/VCPU Memory Disk input/output (I/O) Networking GPU Custom hardware and peripherals Are there any environmental limitations? Power Offline/air-gapped Climate control COTS versus custom-built hardware Dell OnLogic™ What mainstream CPU/hardware platforms are available? Xeon™ Core™ Atom™ Ryzen™ Advanced RISC Machine (ARM™) RISC-V® Power® and IBM Z® Summary 4 Chapter 4: Applying Design Requirements Criteria – the Operating System Matching an operating system to your base hardware platform IBM Power IBM System z RISC-V ARM Driver support, vendor support, and stability Enterprise versus community distributions of Linux Lifecycle of operating systems versus your solution Hard costs versus soft costs Hardware costs Software costs Soft costs Summary Part 2: Design Components 5 Chapter 5: Basic Needs in My Build Chain Technical requirements Software supply chain control Source code control Automation and tool integration – a brief overview Security scanning, testing, and remediation Exercise – executing a network port scan Manifest and configuration tracking Exercise – tracking changes in your product Update control mechanisms Exercise – building custom software packages Exercise – signing your custom RPM package Exercise – creating a custom DNF repository Exercise – configuring your solution to use your custom repository Summary 6 Chapter 6: Disk Encryption Technical requirements Introduction to LUKS Basic implementation review Implementing LUKS on an appliance with automated keys Exercise – implementing LUKS with stored keys and leveraging the crypttab file Is recovery possible? Summary 7 Chapter 7: The Trusted Platform Module What is TPM? The history of TPM Configuring TPM by example Exercise – enabling TPM 2 in conjunction with LUKS encryption Summary Join our community on Discord 8 Chapter 8: Boot, BIOS, and Firmware Security Deep dive into various booting system components Understanding boot-level security using examples Accessing the UEFI configuration What is Secure Boot? Possible threats in firmware Summary 9 Chapter 9: Image-Based Deployments Technical requirements Introducing image-based Linux deployments rpm-ostree and atomic images bootc and bootable container images Special tooling and support infrastructure differences Limitations of image-based deployments rpm-ostree image limitations bootc bootable container image limitations Updating and rolling back changes Upgrade of operating system version in place Practical exercises Exercise 1 – preparing the environment Exercise 2 – creating a container file Exercise 3 – creating an installer Exercise 4 – initial installation Exercise 5 – creating an updated container Exercise 6 – updating your system Summary 10 Chapter 10: Childproofing the Solution: Protection from the End-User and Their Environment Introduction to child-proofing (i.e., protecting the appliance from the end-user) Ensuring hardware-level protections Tamper-proofing with BIOS security USB disablement Case tamper-proofing Operating-system-level and application protections Minimizing access to root SUDO and restricting console access Non-interactive LUKS encryption Keeping users in the application space Application auto-launch at boot Building a UI to simplify configuration while providing a great User Experience (UX) Initial config – text UI Initial config – web UI Update controls – text UI Factory reset controls Summary Part 3: The Build Chain, Appliance Lifecycle, and Continuous Improvement 11 Chapter 11: Knowing the Threat Landscape – Staying Informed Navigating the information and disinformation online Government resources Commercial resources Community resources Knowing what vulnerabilities can impact your builds Running smart searches based on your components Being part of the solution Contribute to the development process Join a user group Summary 12 Chapter 12: Are My Devices’ Communications and Interactions Secure? Technical requirements Bus types and issues USB Serial port The CAN bus Enhancing security with certificates Exercise 1: Creating a self-signed certificate Exercise 2: Adding a certificate to your custom repository server Confirming that your networking is secure Firewalls The command line Web console Graphical UI-based tools Limitations of legacy hardware and software Validating your solution before shipping Summary 13 Chapter 13: Applying Government Security Standards – System Hardening Technical requirements Adherence to key US government standards How do I implement this? Implementation of security standards Validation as part of the QA process Exercise: Installing the OpenSCAP tools and running a scan Example: Using the OpenSCAP Workbench Implementation as part of your continuous integration/continuous deployment (CI/CD) process How do I certify my solution? FIPS certification re-branding by vendors Summary 14 Chapter 14: Customer and Community Feedback Loops Use case development User groups Executive roundtables Community feedback loops Summary Closing the loop Putting all the pieces together Staying engaged Join our community on Discord Index Other Books You May Enjoy _Int_CQF4wmdd _heading=h.1fob9te _ttn1yjutk2c _heading=h.3znysh7 _l0bwa172trqq _191z2sio16m7 _2rfkuy7iguv6 _zihd3wifcxie _b45gm8t5917d _9ham9owshudi _9ywprqusim0o _sy1cz6n42azi _n8e44xc6qbfy _Int_ThL1iXY5 _o5wim0bedcf _sltq70o0qj8f _9lonh7j12a56 _kdpn3rowxq6e _heading=h.44sinio _ws24h0ch9qoj _3zd0wajwxrgu _8077pwrruux3 _5ebhozk6rpq6 _s2kcham53ulv _8kzezj3h3yzf _kpwll6y4m5m0 _oxjwmo2mc0bp _th5682mo9cxl _1gmgztl96hic _25thydqbge5 _lm3twncpvcur _tjb17sii2e0p _o0hbnkdwhbfd _56l78mnx9ccp _a8przqbi10cv _y45f46nhzedw _3ouxt2igf5m7 _p2gc6dz55hz1 _w084yjxui5oa _zfu1wdfx0qvy _90hopnct1093 _g2hv6t9jnnfp _yttfnjsevgxd _jrf0t4fbulqd _keo8gihe3zo6 _qnttiuy7icdl _eqh3wkdx1iut _opiwmsr2elhp _oua691ru8joi _3znlvzkywffh _eps54j4fc5pq _cpyio45x9tzu _plomenh94at _pjknbiwqkx5q _qg1t6d2pwg5f _ermnmmpqkz37 _ais2q7zesq14 _9919lmx531f0 _l4r3mneadlq9 _hpb6rndkkwi8 _5mgkbglc2cx6 _s6xqj2fc0g12 _ddg2xh4lcwpc _ub9mtoctozb _tyx5h4jjssw _wkfrg445iarw _c5n54496fue3 _57t90yui8d97 _2hjml45ruqzr _x6lprbfl1rkm _hjuxld22t9s9 _jwzhgd9ev6cr _3ygestpe7n7l _5o33mbxjmnk9 _map9ixemo179 _o8yejvcc64un _nnrss6xbij3n _ck9ltei3awmh _xlqrlmwnzdhj _wghp5qkvy34b _z2599xe4k5ze _jabp04w62ibs _q298uomzroc3 _oxzvhbq8hkk _lcclwn4swx00 _Int_b34sDkaa _stpdnmtobcd8 _zfffoptpmebi _v98jl7ebnn2e _90xh288et237 _n1uv42kmdp1r _viwljq7v5dft _6t084t98kcmn _3zo4yj752t5e _8qrwiqaozngj _ixqcegtpwvka _Int_bm6eODIT _Int_u6yP80K2 _Int_P58m4MME _c2f1dmgwh17w _Int_pcPpq3hp _Int_z8jgqlrW _6cxygg5tvj0f _Int_Y2T14KR0 _Int_ZIOKYHFZ _593grhc60m4d _Int_NkQgm84Z _wh4p5rr8ucti _xpbbn84fmk4z _lqwu2wgeycsd _p26465kiaeo5 _45z11usp6cye _Int_OtocblYD _hpewfh6wuhdh _Int_OJRHvgLf _eyb9ct5p4pij _p1h101bqjk39 _2he8s7wo6huz _5qdrudxvlteg _Int_2VJjXZwB _Int_WbZTcucM _Int_GabHbfKo _i586pul6ghxt _Int_piJaIrHc _Int_o98f1Chr _Int_QThqUgs8 _xbhsn6di179x _p2566l6d7gmz _Int_p0pQPe6v _veux9scnnv0o _3znysh7 _x47u2w3skv7k _2et92p0 _eo378fsr0nb8 _7xzj6rwguenn _yvnt5sey3q0r _jlme6etw9iqf _3dy6vkm _jrqxfkebjv25 _Int_Vd99oigZ _p4uc10wr0238 _ptziqxs6ho2p _3f44aj7bwr9v _bsjvxcufg5mb _Int_Naikpzjq _xeqpdz51v7q _dhvtvzw0se4p _x1wxeyhc4aiu _hzwtgq8ggd5i _59cv7vx85o26 _gxzkcyn7fauq _2mie7p9w2n4m _xyn6hv7lyhfh _ra2fx31rlpek _rec65sqsety0 _gdao52vaup5p _2f4v1op6s6uw _weleffr0p6lh _7sm9aljwuamf _dsbh03d3mc1z _id1ytzhwrcld _Int_DGMnjacf _8uh45femubf _a13ukuhrh781 _a0pnbay3kt6x _hgrcxt3wuxqo _8p57p1o6wxmi _aqm0w05k9pvs _55a9eyqia5fq _4c6fjyqvnoen _gkp81r9tn9ko _fs44z2yfb33e _2z8dqj9x6jfy _jctezp9hm6oi _Int_UuYTbTDo _nqcsb18h53n _y23s4hmevlmu _hotol3o5a3xn _gs9bxhcze5lk _wk91e18ibfr3 _j6hsm2agysjt _oegbv1masbkt _92jbe8qi87ch _c4bjkflbh6mf _sf8qvygpwqnx _pji1xlkf9ynn _7fm0h1a2ttko _bi2iy01ffp0f _memaahyl3998 _Int_OD5yMmB0 _jb0hd7y5cwjl _4nq75r1zul6b _Hlk191407351 _ugl8k4dzrg5s _Hlk191407502 _qf7woiy1tf90 _biww5k1f0eke _Int_NzMfKGun _juk168djf4fh _Hlk191408452 _bkv0koeuw7ue _Hlk191408673 _ws47uq24sbd4 _7hpyjw6soybv _38fvxeanmwp8 _qmfax9o0c9v7 _pqap56y0mh0c _txlzardppfiz _jza14zc2irct _Hlk191904407 _Hlk191904091 _1fob9te _Int_OwpdakFv _3znysh7 _2et92p0 _7o10xsqqc9wr _8bbkjjchmd6p _ttk2mk1w1v3j _Hlk191908463 _9l29m5tixr4q _u1r8s8g65u0h _7cl9i9avund5 _gr133y9acplh _3dy6vkm _k963nxpisw7a _ki8f74kwelck _pipazq9954ee _Int_QfFfwVjU _3wq0hxoumh97 _lqhhyuq7o05z _pr5z946n6pcg _23o20jx2799b _1voa5nxiwl0w

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF