温馨提示×

debian exploit怎么防止入侵

小樊
35
2026-10-04 16:01:50
栏目: 网络安全

下面从运维安全角度讲“如何防止 Debian 被 exploit / 入侵”,不提供任何攻击利用方法,只讲防御。


一、系统与补丁管理(最关键)

  1. 及时更新系统
sudo apt update
sudo apt upgrade -y
sudo apt dist-upgrade -y
  • 开启自动安全更新:
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
  1. 关注安全公告
  • Debian Security:https://www.debian.org/security/
  • 订阅安全邮件列表

二、最小化安装与服务

  1. 只装必要软件
sudo apt install --no-install-recommends 软件名
  1. 关闭无用服务
systemctl list-unit-files --type=service
sudo systemctl disable 服务名
sudo systemctl stop 服务名
  1. 禁止 root 远程登录
sudo nano /etc/ssh/sshd_config

修改:

PermitRootLogin no

重启:

sudo systemctl restart ssh

三、SSH 安全防护

  1. 使用密钥登录
ssh-keygen -t ed25519

禁用密码登录:

PasswordAuthentication no
  1. 更改 SSH 端口
Port 22222
  1. 限制登录 IP(可选)
sudo apt install ufw
sudo ufw allow from 你的IP to any port 22222

四、防火墙与网络防护

  1. 启用 UFW
sudo ufw enable
sudo ufw default deny incoming
sudo ufw allow 22222/tcp
sudo ufw allow 80,443/tcp
  1. 防止暴力破解
sudo apt install fail2ban

配置文件:

/etc/fail2ban/jail.local

五、权限与审计

  1. 最小权限原则
  • 不用 root 跑业务
  • 使用 sudo
  1. 检查异常用户
cat /etc/passwd
last
  1. 开启审计
sudo apt install auditd
sudo auditctl -w /etc -p wa -k etc_change

六、内核与安全加固

  1. 开启自动更新内核
  2. 使用 AppArmor / SELinux
sudo apt install apparmor
sudo aa-status
  1. 禁用危险模块(如不必要)
# /etc/modprobe.d/blacklist.conf
blacklist dccp
blacklist sctp

七、日志与监控

  • 定期看日志:
/var/log/auth.log
/var/log/syslog
  • 使用监控工具(如 Prometheus + Grafana、Wazuh)

八、备份(最后底线)

rsync / 备份服务器

或:

borgbackup

总结一句话

Debian 防入侵 = 及时打补丁 + 最小服务 + SSH 加固 + 防火墙 + 日志监控 + 备份

如果你愿意,我可以:

  • 给你一份 Debian 安全基线检查清单
  • 或按 服务器用途(Web / 数据库 / 内网) 定制方案

0 踩