DFIM — Deterministic Firmware Integrity Matrix

IEC 62443 firmware integrity enforcement suite

View the Project on GitHub Ahmadsi70/DFIM

🔐 DFIM — Deterministic Firmware Integrity Matrix

Rust License CI Fuzzing Formal Verification CodeQL

Enterprise-grade firmware integrity enforcement from UEFI to kernel to userspace. Deterministic Merkle-tree verification with Hamming FEC, eBPF LSM probes, UEFI boot guard, and formal proofs — all in Rust.


🏆 Benchmark: 95/100 — A+

Dimension Score Grade
Merkle Tree Integrity 100/100 A+
SHA-256 Throughput (2 GB/s) 100/100 A+
eBPF Enforcement (<1 µs lookup) 95/100 A+
Boot Validation (155 µs / 256 KB) 100/100 A+
Real Provisioner/Verify (~7 ms) 75/100 B+
API Concurrency (116K ops/s) 95/100 A+
Fleet Simulation (650K nodes/s) 100/100 A+

Verified against 735 real-world security files — 99.86% tamper detection, 100% provision/verify on CVE exploits, malware patterns, firmware images, and adversarial edge cases. Full report


✨ Features

🛡️ Multi-Ring Integrity

| Layer | Platform | Technology | |——-|———-|————| | Ring -1 (Hardware) | UEFI + TPM 2.0 | DFIMBOOT v2 signed manifests, P-256 ECDSA, anti-rollback | | Ring 0 (Kernel) | Linux | eBPF LSM probes, IMA appraisal, DenyEvents | | Ring 1 (Boot) | Windows | UEFI boot guard intercepts bootmgfw.efi | | Ring 3 (Userspace) | Windows + Linux | CLI provisioner, REST API, WASM plugins |

🔬 Cryptography

🏢 Enterprise Management

✅ Formal Verification

🔗 Supply Chain Security


🚀 Quick Start

📥 Direct Download (No Build Required)

Grab the latest binary for your platform from Releases:

Platform Download
🐧 Linux x86_64 dfim-linux-x86_64.tar.gz
🪟 Windows x86_64 dfim-windows-x86_64.zip
🔐 UEFI x86_64 dfim-uefi-x86_64.tar.gz

🛠️ Build from Source

# Install Rust 1.91.1
rustup install 1.91.1

# Clone & build
git clone https://github.com/Ahmadsi70/DFIM.git
cd DFIM

# Set your encryption key (IEC 62443 CR 1.8)
export DFIM_CRYPTO_KEY="$(openssl rand -hex 32)"   # Linux/macOS

cargo build --release -p dfim_cli_provisioner
./target/release/dfim-provisioner provision /path/to/boot_image.bin
./target/release/dfim-provisioner verify /path/to/boot_image.bin

🐳 Run with Docker

# Clone, set env, and launch
git clone https://github.com/Ahmadsi70/DFIM.git
cd DFIM/deploy
cp .env.example .env        # Edit .env with your passwords
docker compose up -d

# Health check
curl http://localhost:3000/health

Or pull the pre-built image:

docker pull ghcr.io/ahmadsi70/dfim-management-api:latest

🏗️ Architecture

DFIM Workspace (7 crates)
═══════════════════════════════════════════════

┌─────────────────────────────────────────────────────┐
│  dfim_core_engine    — Layer-0: SHA-256, Merkle,    │
│                        Hamming FEC, FIPS, KDF       │
├─────────────────────────────────────────────────────┤
│  dfim_cli_provisioner — CLI: provision, verify,     │
│                          recover, attestation        │
├─────────────────────────────────────────────────────┤
│  dfim_windows_uefi    — UEFI boot guard for Windows │
├─────────────────────────────────────────────────────┤
│  dfim-ebpf / dfim-ebpf-user — Linux eBPF LSM probes │
├─────────────────────────────────────────────────────┤
│  dfim_management_api  — REST API, RBAC, SIEM export │
├─────────────────────────────────────────────────────┤
│  dfim_plugin_sdk      — WASM sandbox for policies   │
├─────────────────────────────────────────────────────┤
│  dfim_host_init       — Evaluation license gate     │
└─────────────────────────────────────────────────────┘

📁 Documentation

Document Description
docs/security/THREAT_MODEL.md Comprehensive threat model
docs/security/ENFORCEMENT_POLICY.md Enforcement policy architecture
docs/security/DFIMBOOT_V2.md Boot security specification v2
docs/security/REMOTE_ATTESTATION.md TPM 2.0 attestation protocol
docs/security/COMPLIANCE_MAPPING.md ISO 27001:2022 mapping
docs/enterprise/ENTERPRISE_SLA.md Service Level Agreements
docs/enterprise/PRODUCT_SECURITY_WHITE_PAPER.md Security white paper
docs/OPERATOR_RUNBOOK.md Operations guide
SECURITY_BENCHMARK_REPORT.md 735-file security benchmark

🧪 Tested & Deployed

Environment Status
Windows 11 (UEFI) ✅ Verified
Ubuntu 24.04 (eBPF) ✅ Verified
QEMU/KVM (Virtualized) ✅ Verified
735 Security Files ✅ 99.86% tamper detection

📜 License

DFIM Community Edition is licensed under GNU AGPL-3.0 — see LICENSE for details. This is a strong copyleft license: if you modify the code and offer it as a network service (SaaS), you must release your changes under the same license (Section 13).

DFIM Enterprise Edition is available under a commercial license that exempts you from AGPL-3.0 network-use obligations. Enterprise adds: TPM attestation, FIPS 140-3 validation, SIEM connectors, WASM plugin SDK, premium support, and SLA. Contact dfim-licensing@example.com for a quote.


🤝 Contributing

We welcome contributions! See CONTRIBUTING.md and our Code of Conduct.

For enterprise or partnership inquiries, please start a discussion.


⭐ Support

If you find DFIM useful:


Deterministic Integrity. Built in Rust.