News
Comparative Quantitative Evaluation of Kernel Hardening Mechanisms in Operating Systems
Abstract
This paper presents a methodology for quantitatively comparing hardening mechanisms in operating system kernels across monolithic, microkernel-based, and embedded systems. Existing guidance and tools are generally limited to individual operating systems and mostly verify whether mechanisms are present or enabled; no unified methodology is available for quantitatively comparing heterogeneous kernels. We develop a taxonomy of 76 mechanisms organized into seven categories. Each mechanism is scored along five dimensions: presence and applicability, default posture, implementation strength, depth of integration into the kernel design, and maturity. Individual scores are aggregated into a composite score using configurable profiles of dimension weights and threat-model-dependent category weights. The composite score is complemented by coverage and implemented-quality metrics that separate breadth from depth of protection. The methodology is applied to nine systems representing three analytical groups: Linux, OpenBSD, NetBSD, Fuchsia (Zircon), GNU Hurd (GNU Mach), seL4, Redox, Tock, and Zephyr. The results show that variation within an architectural class may exceed the differences between classes. Thus, the composite score depends not only on kernel architecture but also on completeness of implementation, default posture, implementation strength, maturity, and maintenance activity. The complete evaluation dataset is made publicly available.
Keywords
Edition
Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 81-108
ISSN 2220-6426 (Online), ISSN 2079-8156 (Print).
DOI: 10.15514/ISPRAS-2026-38(4)-20
For citation
Full text of the paper in pdf (in Russian)
Back to the contents of the volume