Protect data and OT operations even when primary Linux is compromised
- Secure Linux applications in isolated partitions
- Pay security-related overheads only when needed
- Seamless communication between partitions
Bunker for Linux offers dual-partition run-time environment composed of:
Open World, a traditional Linux system that can be externally exposed (e.g., network connectivity)
Bunker, a strongly isolated, security-hardened Linux execution environment
Core Features
Pre-installed and pre-configured security hardening, including encrypted filesystem, attack detection and recovery, and countermeasures for side-channel attacks
Seamless communication mechanisms between Open World and Bunker that preserve security
Secure update procedures and built-in support for containerization (e.g., Docker)
Three security profiles to balance security with performance: hard, vigorous, and extreme
The Architecture
Key features
Secure Linux Application in Isolated Partitions: Partitioning between Open World and Bunker employs next-generation Hypervisor technology
Pay Security-Related Overheads only When Needed: Involve resource-expensive security
countermeasures for critical component only (i.e., within Bunker), while keeping the performance of non-critical software unaffected
Confidentiality, Integrity & Availability (CIA) Enforcement: Ensures only authorized applications can access sensitive data and prevents tampering
Zero-Trust approach: Even if Open World is breached, Bunker for Linux prevents lateral movement or access to protected applications running within Bunker
Ecosystem
Chip Vendors: NXP, AMD, ST, Altera
Architecture: Armv8/9-A
Download the product description
FAQ
What is Bunker for Linux?
Bunker for Linux is a ready-to-use security solution composed of a set of embedded software components developed to harden Linux-based systems and improve runtime protection against modern and ever-evolving cyber threats.
It helps organizations increase resilience while preserving system stability and operational performance.
Does Linux hardening impact embedded system performance?
Bunker for Linux is designed to provide advanced protection while minimizing performance impact, achieving a better overall performance of the device with respect to the traditional solutions that apply security mechanisms to the entire application. Bunker for Linux allows you to pay security-related overhead only when needed, leaving the non-critical part to perform at high performance.