Linux Hardening¶
Reducing the attack surface of Linux hosts through configuration.
Why It Matters¶
Linux servers run a large share of internet-facing infrastructure, so hardening them directly reduces exposure. As with Windows, most of the work is removing defaults that favor convenience over security.
Reference¶
Baselines¶
| Baseline | Source |
|---|---|
| CIS Benchmarks | CIS Linux Benchmarks |
| DISA STIGs | DoD STIGs |
| Vendor guides | Ubuntu, RHEL, and SUSE security guides |
Key Areas¶
| Area | Controls |
|---|---|
| Accounts | Strong password policy, no shared accounts, lock unused accounts |
| SSH | Key-based auth, disable root login (PermitRootLogin no), disable password auth where possible, change defaults |
| Privilege | Least-privilege sudo rules, audit /etc/sudoers |
| Services | Disable and remove unneeded services and packages |
| Firewall | ufw or firewalld with a default-deny inbound policy |
| Updates | Timely patching, unattended security updates |
| Logging | Centralize logs, enable auditd for key events |
| File integrity | AIDE or similar for critical files |
| MAC | SELinux or AppArmor in enforcing mode |
Quick Checks¶
sudo ss -tulnp # listening services
sudo grep PermitRootLogin /etc/ssh/sshd_config
sudo ufw status verbose # firewall state
systemctl list-unit-files --state=enabled # enabled services
How I Use It¶
I apply a CIS benchmark with a tool like OpenSCAP or an Ansible role rather than by hand, then tune exceptions. SSH and the firewall are the first priorities on any internet-facing host, followed by trimming services and turning on auditd.