Linux14 min read·

Expert Guide to Linux Security: Harden Your Systems Like a Pro

Master Linux security with this expert guide. Learn system hardening, firewall configuration, SSH security, SELinux, and security auditing techniques.

Linux Security Model

Linux is inherently more secure than many operating systems due to its permission model, open-source nature, and strong community oversight. However, a default Linux installation is not hardened. Security professionals must actively configure and harden Linux systems to protect against threats.

The Linux security model is built on several pillars:

  • User and group permissions - Least privilege access control
  • Process isolation - Separation of services and resources
  • Kernel security modules - SELinux, AppArmor, seccomp
  • File system protections - Permissions, attributes, encryption
  • Network controls - Firewalls, packet filtering, network namespaces

User Permissions and Access Control

Principle of Least Privilege

Never run services as root unless absolutely necessary. Create dedicated service accounts with minimal permissions:

sudo useradd -r -s /usr/sbin/nologin myservice
sudo chown -R myservice:myservice /opt/myservice

Sudo Configuration

Configure sudo to limit which commands users can run as root:

visudo

Add specific command permissions:

username ALL=(root) /usr/bin/systemctl restart nginx

Password Policies

Enforce strong password policies:

sudo apt install libpam-pwquality

Configure in /etc/security/pwquality.conf:

  • Minimum password length: 12 characters
  • Require uppercase, lowercase, numbers, and special characters
  • Prevent password reuse (last 12 passwords)

Firewall Configuration

iptables/iptables-nftables

The Linux kernel firewall provides packet filtering and network address translation:

# Allow established connections
sudo iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

# Allow SSH
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT

# Allow HTTP/HTTPS
sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT

# Drop everything else
sudo iptables -P INPUT DROP

UFW (Uncomplicated Firewall)

UFW provides a simpler interface for managing firewall rules:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow ssh
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

SSH Hardening

SSH is the most common remote access method and a frequent attack target:

Key-Based Authentication

Disable password authentication and use SSH keys:

# Generate a key pair
ssh-keygen -t ed25519 -a 100

# Copy the public key to the server
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server

SSH Server Configuration

Edit /etc/ssh/sshd_config:

PermitRootLogin no
PasswordAuthentication no
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers specificuser
Protocol 2

Fail2Ban

Install fail2ban to automatically ban IPs after failed login attempts:

sudo apt install fail2ban
sudo systemctl enable fail2ban

File Integrity Monitoring

Monitor critical files for unauthorized changes:

AIDE (Advanced Intrusion Detection Environment)

sudo apt install aide
sudo aideinit

Run periodic checks:

sudo aide --check

Tripwire

Tripwire provides file integrity monitoring with detailed reporting:

sudo apt install tripwire

Log Analysis

Centralized logging is essential for security monitoring:

Rsyslog Configuration

Configure rsyslog to forward logs to a central server:

# /etc/rsyslog.d/remote.conf
*.* @@logserver:514

Logwatch

Install logwatch for automated log analysis:

sudo apt install logwatch
sudo logwatch --output stdout --detail high

Essential Log Files

  • /var/log/auth.log - Authentication attempts
  • /var/log/syslog - System events
  • /var/log/kern.log - Kernel events
  • /var/log/apache2/access.log - Web access logs

SELinux/AppArmor

SELinux

SELinux (Security-Enhanced Linux) provides mandatory access control:

# Check SELinux status
getenforce

# Set to enforcing
sudo setenforce 1

AppArmor

AppArmor confines programs to a limited set of resources:

# Check AppArmor status
sudo aa-status

# Enforce a profile
sudo aa-enforce /etc/apparmor.d/usr.sbin.apache2

Security Auditing Tools

Lynis

Lynis performs comprehensive security auditing:

sudo apt install lynis
sudo lynis audit system

OpenSCAP

OpenSCAP provides compliance checking against security standards:

sudo apt install libopenscap8
sudo oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_standard /usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml

Security Hardening Checklist

Use this checklist to harden any Linux system:

  1. Update all packages: sudo apt update && sudo apt upgrade -y
  2. Remove unnecessary packages and services
  3. Configure firewall (deny all, allow specific)
  4. Harden SSH (key-based auth, disable root login)
  5. Enable automatic security updates
  6. Configure log monitoring and forwarding
  7. Install and configure fail2ban
  8. Set up file integrity monitoring
  9. Run Lynis audit and address findings
  10. Document all configuration changes

Practice Linux Security in XpertClass Labs

XpertClass provides free, hands-on Linux security labs. Practice firewall configuration, SSH hardening, privilege escalation, and system auditing in isolated Docker environments.

Ready to practice?

Apply what you learned with free hands-on labs on XpertClass. Deploy real Docker sandboxes — no setup required.