| 系统与补丁 |
sudo apt update && sudo apt full-upgrade;sudo apt install unattended-upgrades;sudo dpkg-reconfigure unattended-upgrades |
自动仅安装安全更新,减少暴露窗口 |
| 防火墙 |
sudo apt install ufw;sudo ufw enable;sudo ufw allow ssh |
默认拒绝入站,按需放行 |
| SSH 加固 |
/etc/ssh/sshd_config:PermitRootLogin no;PasswordAuthentication no;Port 2222;AllowUsers youruser;sudo systemctl restart sshd |
密钥登录优先,限制可登录账户,变更端口需同步更新防火墙 |
| 恶意软件扫描 |
sudo apt install clamav clamtk;sudo freshclam;clamscan -r --move=/quarantine /home |
更新病毒库后扫描;对共享/下载目录定期查杀 |
| 入侵防护 |
sudo apt install fail2ban;sudo systemctl enable --now fail2ban |
自动封禁暴力破解来源 |
| 完整性/Rootkit 检测 |
sudo apt install chkrootkit rkhunter;sudo chkrootkit;sudo rkhunter --check |
定期离线或按计划巡检 |
| 合规与审计 |
sudo apt install lynis;sudo lynis audit system |
获取安全基线并逐项整改 |