OpenBSD: A new feature added to testing snapshots of new OpenBSD releases will create a unique kernel every time an OpenBSD user reboots or upgrades their computer.
This feature is called KARL, which stands for Kernel Address Randomized Link, and works by relinking internal kernel files in random order, creating a unique kernel binary blob each time.
Currently, in stable versions of OpenBSD the kernel uses a predefined order to relink and load internal files into the kernel binary. This results in the same kernel for all users.
OpenBSD with KARL and not ASLR
KARL was developed by Theo de Raadt, and works by creating a new kernel binary during installation, upgrade, and boot time. If the user boots, upgrades, or reboots their machine, a newly created kernel will replace the existing kernel, and the operating system will create a new kernel binary to be used on the next boot/upgrade/reboot.
KARL should not be confused with ASLR, or Address Space Layout Randomization, a technique that randomizes memory addresses when an application is executed. This way, exploits cannot target a specific memory area that the attacker knows an application or kernel is running.
Instead, KARL creates kernel binaries with random internal structures, so that exploits cannot attack internal kernel functions, pointers, or objects. A technical explanation is available at the link below.
https://undeadly.org/cgi?action=article&sid=20170701170044&mode=expanded&count=9
The feature was developed over the last two months
Work on this feature began in May and was first discussed in mid-June on the OpenBSD technical mailing list. KARL was recently added to snapshot releases of OpenBSD 6.1.
This new feature appears to be unique to OpenBSD, as we don't know of anything similar for Linux.
Linux just added support for Kernel Address Space Layout Randomization (KASLR), a feature that ports ASLR into the kernel itself, loading the kernel at a random memory address.
This feature was enabled by default in Linux 4.12, released last week. The difference between the two is that KARL loads different kernel binaries in the same place, while KASLR loads the same kernel binary in random locations. Same target, different paths.
As for Windows, KARL is not supported, but Microsoft has been using KASLR for many years.
It should be mentioned that OpenBSD's new feature seems to provide much more security than the solutions used by Microsoft and Linux.
Maybe after several tests we will see KARL on other operating systems.
