Expert Guide to Linux Security: Harden Your Systems Like a Pro
Master Linux security with this expert guide. Learn system hardening, firewall configuration, SSH security, SELinux, and security auditing techniques.
Linux Security Model
Linux is inherently more secure than many operating systems due to its permission model, open-source nature, and strong community oversight. However, a default Linux installation is not hardened. Security professionals must actively configure and harden Linux systems to protect against threats.
The Linux security model is built on several pillars:
- User and group permissions - Least privilege access control
- Process isolation - Separation of services and resources
- Kernel security modules - SELinux, AppArmor, seccomp
- File system protections - Permissions, attributes, encryption
- Network controls - Firewalls, packet filtering, network namespaces
User Permissions and Access Control
Principle of Least Privilege
Never run services as root unless absolutely necessary. Create dedicated service accounts with minimal permissions:
sudo useradd -r -s /usr/sbin/nologin myservice
sudo chown -R myservice:myservice /opt/myservice
Sudo Configuration
Configure sudo to limit which commands users can run as root:
visudo
Add specific command permissions:
username ALL=(root) /usr/bin/systemctl restart nginx
Password Policies
Enforce strong password policies:
sudo apt install libpam-pwquality
Configure in /etc/security/pwquality.conf:
- Minimum password length: 12 characters
- Require uppercase, lowercase, numbers, and special characters
- Prevent password reuse (last 12 passwords)
Firewall Configuration
iptables/iptables-nftables
The Linux kernel firewall provides packet filtering and network address translation:
# Allow established connections
sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
# Allow SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
# Allow HTTP/HTTPS
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT
# Drop everything else
sudo iptables -P INPUT DROP
UFW (Uncomplicated Firewall)
UFW provides a simpler interface for managing firewall rules:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow ssh
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
SSH Hardening
SSH is the most common remote access method and a frequent attack target:
Key-Based Authentication
Disable password authentication and use SSH keys:
# Generate a key pair
ssh-keygen -t ed25519 -a 100
# Copy the public key to the server
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server
SSH Server Configuration
Edit /etc/ssh/sshd_config:
PermitRootLogin no
PasswordAuthentication no
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers specificuser
Protocol 2
Fail2Ban
Install fail2ban to automatically ban IPs after failed login attempts:
sudo apt install fail2ban
sudo systemctl enable fail2ban
File Integrity Monitoring
Monitor critical files for unauthorized changes:
AIDE (Advanced Intrusion Detection Environment)
sudo apt install aide
sudo aideinit
Run periodic checks:
sudo aide --check
Tripwire
Tripwire provides file integrity monitoring with detailed reporting:
sudo apt install tripwire
Log Analysis
Centralized logging is essential for security monitoring:
Rsyslog Configuration
Configure rsyslog to forward logs to a central server:
# /etc/rsyslog.d/remote.conf
*.* @@logserver:514
Logwatch
Install logwatch for automated log analysis:
sudo apt install logwatch
sudo logwatch --output stdout --detail high
Essential Log Files
/var/log/auth.log- Authentication attempts/var/log/syslog- System events/var/log/kern.log- Kernel events/var/log/apache2/access.log- Web access logs
SELinux/AppArmor
SELinux
SELinux (Security-Enhanced Linux) provides mandatory access control:
# Check SELinux status
getenforce
# Set to enforcing
sudo setenforce 1
AppArmor
AppArmor confines programs to a limited set of resources:
# Check AppArmor status
sudo aa-status
# Enforce a profile
sudo aa-enforce /etc/apparmor.d/usr.sbin.apache2
Security Auditing Tools
Lynis
Lynis performs comprehensive security auditing:
sudo apt install lynis
sudo lynis audit system
OpenSCAP
OpenSCAP provides compliance checking against security standards:
sudo apt install libopenscap8
sudo oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_standard /usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
Security Hardening Checklist
Use this checklist to harden any Linux system:
- Update all packages:
sudo apt update && sudo apt upgrade -y - Remove unnecessary packages and services
- Configure firewall (deny all, allow specific)
- Harden SSH (key-based auth, disable root login)
- Enable automatic security updates
- Configure log monitoring and forwarding
- Install and configure fail2ban
- Set up file integrity monitoring
- Run Lynis audit and address findings
- Document all configuration changes
Practice Linux Security in XpertClass Labs
XpertClass provides free, hands-on Linux security labs. Practice firewall configuration, SSH hardening, privilege escalation, and system auditing in isolated Docker environments.
Related Articles
Ready to practice?
Apply what you learned with free hands-on labs on XpertClass. Deploy real Docker sandboxes — no setup required.