Technology Today

Microsoft has published details about a new project called Integrity Policy Enforcement (IPE) that it has been working on for the Linux kernel.IPE is a Linux Security Module (LSM) which are optional add-ons for the Linux kernel designed to enable additional security features.
In its documentation page, Microsoft explained how IPE attempts to solve the issue of code integrity, saying:IPE is a Linux Security Module, which allows for a configurable policy to enforce integrity requirements on the whole system.
It attempts to solve the issue of code integrity: that any code being executed (or files being read), are identical to the version that was built by a trusted source.
Simply stated, IPE helps the owner of a system ensure that only code they have authorized is allowed to execute.On Linux systems with IPE enabled, system administrators can create a list of binaries that are allowed to execute and add verification attributes which the kernel needs to check for each binary before allowing it to run.
If a binary has been altered by an attacker, IPE has the ability to block the execution of the malicious code.According to Microsoft, IPE is not intended for general-purpose computing as it was designed for very specific use cases when security is of the utmost importance and administrators need to be in full control of what code runs on their systems.Some examples of systems that could benefit from using the software giant's new LSM include embedded systems such as network firewall devices running in a data center and Linux servers that are running strict and immutable configurations and applications.Microsoft has published the specifications for the new IPE module but it is currently in a RFC or request for comments state.
It will likely be some time before IPE ships with the actual Linux kernel.The Linux kernel already includes a LSM for code integrity called Integrity Measurement Architecture (IMA).
However, Microsoft says that IPE differs from IMA because it has no dependency on the filesystem metadata and because IPE attributes are deterministic properties that exist solely in the kernel.Via ZDNet





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Apple fans rushing for ₤ 35 iPhone 16 Pro Max as Sky uses payday deal


'I visited Chinese city which is like sci-fi movie with robots and noiseless trains'


Top Tech: Amazon's best early Prime Day deals including Ring, Tefal and Nespresso


Brits now 'obsessed' with health tracking and say it's key to motivation


Virgin Media is distributing complimentary wise TVs in surprise seven-day sale


O2 confirms UK network switch off and the exact date your phone might quit working


Samsung and Google have a new Android competitor that's like Nothing you've seen before


'Spectacular' Samsung Galaxy S25 Ultra gets £10 a month price cut


Sky users given 48-hour cost alert and your costs could increase tomorrow


Never ever miss your favourite television series when on vacation with basic travel hack


Amazon may offer big reason to ditch your Fire TV Stick next week and try something new


Samsung and Google smartphone deals consist of free earbuds and smartwatches


Everyone using Google Chrome must restart their browser now - don't ignore new alert


iPhone users surprised after finding 'concealed' hack to organise home screen


Sky dishes out brand-new iPhone 16 at 'lowest ever' rate, not surprising that it's offering fast


Argos shoppers can get a free 40-inch Hisense TV by doing one thing


Immediate alert for everyone with a Gmail account - do not overlook 6 important brand-new rules


BBC iPlayer is rivalling Sky TV with a vital free upgrade - check your settings now