1. SSH-Lockdown
- Root-Login deaktivieren
- Nur Key-Auth erzwingen
- Standard-Port 22 → 2222 ändern
- Fail2ban mit SSH-Jail
- 2FA mit Google Authenticator
2. iptables / nftables Firewall
DROP-Default auf INPUT, GeoIP-Filterung, Rate-Limiting pro IP.
3. CrowdSec
Verteilte Threat-Intelligence-Community.
4. Automatische Sicherheitsupdates
unattended-upgrades konfiguriert nur für Sicherheit.
5. CIS Benchmark + Lynis Audit
Lynis monatlich ausführen. Hardening-Score > 80 anstreben.
Basis-Befehle
Einige konkrete Befehle, um sofort mit dem Hardening zu beginnen:
# SSH lockdown + fail2ban (comenzi reale)
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl reload ssh
sudo apt -y install fail2ban unattended-upgrades
sudo systemctl enable --now fail2ban
sudo lynis audit system # scor de hardening
Kernel-Hardening (sysctl)
Einige sysctl-Einstellungen, die die Angriffsflaeche auf Netz- und Kernel-Ebene reduzieren:
cat >/etc/sysctl.d/99-hardening.conf <<'EOF'
net.ipv4.conf.all.rp_filter=1
net.ipv4.tcp_syncookies=1
net.ipv4.conf.all.accept_redirects=0
net.ipv4.conf.all.accept_source_route=0
kernel.randomize_va_space=2
kernel.kptr_restrict=2
fs.protected_hardlinks=1
fs.protected_symlinks=1
EOF
sysctl --system
Dateiintegritaet (AIDE) + Auditing (auditd)
Sie initialisieren die AIDE-Datenbank und setzen auditd-Regeln fuer kritische Dateien:
apt -y install aide auditd
aideinit && mv /var/lib/aide/aide.db.new /var/lib/aide/aide.db
aide --check # ruleaza zilnic din cron
# audit pe fisiere sensibile
auditctl -w /etc/passwd -p wa -k identity
auditctl -w /etc/ssh/sshd_config -p wa -k sshd
ausearch -k identity | tail
AppArmor: Profil erzwingen
Sie isolieren einen Dienst mit AppArmor im Enforce-Modus:
apt -y install apparmor-utils
aa-status # ce profile sunt incarcate
aa-enforce /etc/apparmor.d/usr.sbin.nginx
aa-logprof # ajustezi din denials reale
journalctl -k | grep apparmor='DENIED'
SSH-2FA + automatische Updates
Sie fuegen SSH einen TOTP-Code hinzu und aktivieren automatische Sicherheitsupdates:
apt -y install libpam-google-authenticator unattended-upgrades
google-authenticator # ca user: scanezi QR in app
# /etc/pam.d/sshd: auth required pam_google_authenticator.so
# /etc/ssh/sshd_config: AuthenticationMethods publickey,keyboard-interactive
dpkg-reconfigure -plow unattended-upgrades
systemctl reload ssh