How to Secure Your Server: 6 Practical Methods


Any IT infrastructure requires reliable protection. Information security is a topic that can't be covered in a couple of lessons. However, there are some basic steps that can help protect against attacks by amateur hackers and bots. In this article, we'll look at how to protect your server using six simple methods.

 

Security Tools and Methods
Protecting a server from hacking always involves a range of measures. These methods can be broadly categorized into the following areas:

Securing communication channels used for system administration and use.
Organizing multiple levels of system security.
Restricting access to infrastructure resources.
Monitoring and auditing systems.
Backup.
Timely software updates (or rollbacks).
Antivirus protection for servers.
Next, we'll look at six practical methods that provide a level of protection that's unattainable for amateur hackers and bots.

Privilege Separation
When organizing access to resources, follow the universal rule: processes and users should have access only to the minimum required for operation. This is especially true for databases and operating systems. The principle of least privilege will help protect your server from unauthorized external access, minimizing damage, as well as from internal threats.

It's best to create a separate account for each administrator, and perform operations that don't require elevated privileges from unprivileged accounts. When using a Microsoft Active Directory environment, periodically check and configure group policies, as this mechanism, in the hands of a malicious administrator or hacker, can lead to serious security breaches.

When working with *nix systems, avoid constantly working as the root account. It's best to disable it and use sudo. Sudo settings can be changed in the /etc/sudoers file or with the visudo command. Here are two useful defaults directives that will help you monitor who is doing what via sudo.

By default, the log is written to syslog. The following setting (in the /etc/sudoers file) aggregates the log entries into a separate file for convenience:

Defaults log_host, log_year, logfile="/var/log/sudo.log"

This option causes sudo to write session text (command log, stdin, stderr, stdout messages, and tty/pty log) to the /var/log/sudo-io directory:

Defaults log_host, log_year, logfile="/var/log/sudo.log"

Mandatory Access Control
The next tip concerns Linux systems and is related to the previous one. Many Linux administrators are content with discretionary access control mechanisms, which are the primary and always active. However, many distributions (AppArmor in Ubuntu, SELinux in RHEL-based systems) have mandatory access control mechanisms. These require more complex OS and service configuration, but they allow for fine-grained access control to file system objects, providing more robust software-based server protection.

Remote OS Administration
When administering the operating system remotely, use secure protocols. For Windows, this is considered RDP, and for Linux, SSH. Although these protocols are secure, additional security can be strengthened.

For RDP, it is advisable to block connections from accounts with blank passwords. This can be done through the "Local Security Policies" setting "Accounts: Allow blank passwords only for console logins." RDP sessions can be protected using the secure transport protocol TLS, which will be discussed later.

By default, user identity verification in SSH is performed using a password. Enabling SSH key authentication increases server security, as a long key is much harder to guess, and you don't need to enter a password (the key is stored on the server). Setting up keys requires just a few simple steps:

Generating a key pair on the local machine:

ssh-keygen -t rsa

Placing keys on a remote station:

ssh-copy-id login@address

If you don't want to use keys, consider Fail2ban, which limits password attempts and blocks IP addresses. It's also a good idea to change the default ports: 22/tcp for SSH, 3389/tcp for RDP.

Firewall Configuration
A proper security system consists of layers. Don't rely solely on access control mechanisms. It's more logical to control network connections before they reach services. That's what firewalls are for.

A firewall provides network-level access control to parts of the infrastructure. Based on a specific set of allow rules, the firewall determines which traffic is allowed through the perimeter. Anything that doesn't meet these rules is blocked. It's worth noting that in Linux, the firewall is part of the kernel (netfilter), so to work in user space, you need to install a frontend: nftables, iptables, ufw, or firewalld.

The first thing to do when setting up a firewall is to close unused ports and leave only those that are expected to be accessed from the outside. For example, for a web server, this would be port 80 (http) and 443 (https). There's nothing inherently dangerous about an open port (the threat may lie in the program behind the port), but it's still better to remove unnecessary ones.

In addition to providing an external security perimeter, firewalls help divide the infrastructure into segments and control traffic between them. If you have publicly accessible services, consider isolating them from internal resources (a DMZ). We also recommend considering intrusion detection and prevention systems (IDS/IPS). These solutions work on the opposite principle: block the security problem and let everything else through.

Virtual Private Networks
Previously, we looked at how to protect a server from hacking. Now let's look at protecting multiple servers. The main purpose of virtual private networks is to securely connect branch offices. Such a network is essentially a logical network over another network (e.g., the internet). Security is provided by cryptography, so the security of connections is independent of the security of the underlying network.

There are many protocols for private networks. The choice depends on the size of the organization, the network, and the required level of security. For a small business or home local area network, classic PPTP is suitable: PPTP can be configured on almost any router or phone. Among its drawbacks are its outdated encryption methods. For high-level security and network-to-network connections, IPsec protocols are suitable, while for network-to-node connections, protocols such as WireGuard and others are suitable. However, these protocols require more detailed configuration than PPTP.

TLS and Public Key Infrastructure
Many application layer protocols were developed at a time when networks were limited to colleges and military establishments, and the web hadn't yet been invented. HTTP, FTP, SMTP, and other popular protocols transmit data in plaintext. If you want to secure a website, the web control panel of an internal service, or email, use TLS.

TLS is a transport layer security protocol designed to securely transmit data over an insecure network. Although TLS is often referred to as SSL (SSL certificate, OpenSSL package), keep in mind that the current version of the protocol is TLS 1.2/1.3. Earlier versions of TLS and the protocol that preceded SSL are considered obsolete.

TLS ensures privacy, data integrity, and resource authentication. The latter is achieved using digital signatures and a public key infrastructure (PKI). A PKI works as follows: the authenticity of a server is determined by an SSL certificate signed by a certification authority (CA). The CA certificate is in turn signed by a higher-level CA, and so on down the chain. Root CA certificates are self-signed, meaning they are trusted by default.

TLS can also be used in conjunction with a virtual private network, for example, by configuring client authentication using SSL certificates or TLS handshake. In this case, it is necessary to independently set up a public key infrastructure (CA server, keys, and node certificates) within the local network.

What's the danger of hackers?
The severity of a threat depends on its type. Attacks are divided into several categories.

The first category involves penetrating the security perimeter. In this case, an attacker gains access to the account of an authorized user of a service or system, such as a database. Compromising privileged accounts poses a threat, as hackers gain access to tools for viewing sensitive information and changing system settings. A critical type of "penetration" involves unauthorized access to the operating system's superuser account. In this situation, a large portion of the infrastructure is at risk.

Another type of attack aims to disable a system. These threats don't involve data leaks, but that doesn't make them any less dangerous. The most notable attacks of this type are DoS and DDoS attacks. These attacks involve attackers overwhelming a server with a flood of requests. The server can't handle the load and stops responding to user requests. Sometimes, a DoS attack can serve as a pretext for other attacks.

Attacks often result in data leaks, financial damage, and reputational damage, so it's important to consider at least a minimum level of security when setting up an IT infrastructure.


Go back
18-09-2025, 05:14