ÏÂÁîÐй¤¾ß£ºÌá¸ßÄãµÄЧÀÍÆ÷Çå¾²ÐÔ
ÏÂÁîÐй¤¾ß£ºÌá¸ßÄãµÄЧÀÍÆ÷Çå¾²ÐÔ
ÔÚµ±½ñÊý×Ö»¯Ê±´ú£¬Ð§ÀÍÆ÷µÄÇå¾²ÐÔ±äµÃÓÈΪÖ÷Òª¡£¹¥»÷ÕßʹÓÃÖÖÖÖÎó²îºÍÊÖÒÕ£¬Ò»Ö±ÊÔͼÈëÇÖЧÀÍÆ÷ϵͳ£¬ÇÔÈ¡Êý¾Ý»òÕß¾ÙÐжñÒâ²Ù×÷¡£ÎªÁ˱£»¤Ð§ÀÍÆ÷µÄÇå¾²£¬ÎÒÃÇÐèÒª½ÓÄÉÖÖÖÖ²½·¥À´±ÜÃâÈëÇÖ¡£ÏÂÁîÐй¤¾ßÊÇÒ»¸öÇ¿Ê¢µÄ¹¤¾ß£¬¿ÉÒÔ×ÊÖúÎÒÃÇÌá¸ßЧÀÍÆ÷µÄÇå¾²ÐÔ¡£±¾ÎĽ«ÏÈÈÝһЩ³£ÓõÄÏÂÁîÐй¤¾ß£¬²¢ÌṩÏà¹ØµÄ´úÂëʾÀý¡£
fail2ban
fail2banÊÇÒ»¿îÓÃÓÚ±ÜÃⱩÁ¦ÆƽâµÄ¹¤¾ß¡£Ëüͨ¹ý¼àÊӵǼʵÑé²¢ÔÝʱեȡÀ´×ÔÌض¨IPµØµãµÄ»á¼û£¬´Ó¶øÓÐÓõرÜÃⱩÁ¦Æƽ⹥»÷¡£ÒÔÏÂÊÇ×°ÖúÍÉèÖÃfail2banµÄʾÀý´úÂ룺
# ×°ÖÃfail2ban sudo apt-get install fail2ban # ½¨Éè×Ô½ç˵µÄjail.localÉèÖÃÎļþ sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local # ±à¼jail.localÎļþ sudo nano /etc/fail2ban/jail.local # ÉèÖÃfail2ban¼àÊÓSSHµÇ¼ʵÑé [sshd] enabled = true port = ssh filter = sshd logpath = /var/log/auth.log maxretry = 3 bantime = 86400 # Æô¶¯fail2banЧÀÍ sudo systemctl start fail2ban # ÉèÖÃfail2banЧÀÍ¿ª»ú×ÔÆô¶¯ sudo systemctl enable fail2ban
µÇ¼ºó¸´ÖÆ
iptables
iptablesÊÇÒ»¿îÓÃÓÚÉèÖúÍÖÎÀíLinuxÄں˷À»ðǽ¹æÔòµÄ¹¤¾ß¡£Ëü¿ÉÒÔÓÐÓõعýÂËÍøÂçÁ÷Á¿£¬×èÖ¹¶ñÒâÇëÇóºÍ¹¥»÷¡£ÒÔÏÂÊÇһЩ³£¼ûµÄiptablesÏÂÁîʾÀý£º
# Çå¿ÕËùÓеÄiptables¹æÔò sudo iptables -F # ÔÊÐíÌض¨IPµØµãµÄ»á¼û sudo iptables -A INPUT -s 192.168.1.100 -j ACCEPT # ÔÊÐíÌض¨¶Ë¿ÚµÄ»á¼û sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT # ¾Ü¾øËùÓÐÆäËûµÄ»á¼û sudo iptables -A INPUT -j DROP # ÉúÑÄiptables¹æÔò sudo iptables-save > /etc/iptables/rules.v4
µÇ¼ºó¸´ÖÆ
logwatch
logwatchÊÇÒ»¿îÈÕÖ¾ÆÊÎö¹¤¾ß£¬¿ÉÒÔ×ÊÖúÎÒÃǼàÊÓЧÀÍÆ÷ÈÕÖ¾²¢²éÕÒDZÔÚµÄÇå¾²ÎÊÌâ¡£Ëü»á°´ÆÚÆÊÎöϵͳÈÕÖ¾Îļþ£¬ÌìÉúÒ×ÓÚÔĶÁµÄ±¨¸æ£¬²¢·¢Ë͸øÖÎÀíÔ±¡£ÒÔÏÂÊÇ×°ÖúÍÉèÖÃlogwatchµÄʾÀý´úÂ룺
# ×°ÖÃlogwatch sudo apt-get install logwatch # ½¨Éè×Ô½ç˵µÄlogwatch.confÉèÖÃÎļþ sudo cp /usr/share/logwatch/default.conf/logwatch.conf /etc/logwatch/conf/logwatch.conf # ±à¼logwatch.confÎļþ sudo nano /etc/logwatch/conf/logwatch.conf # ÉèÖÃlogwatch·¢Ëͱ¨¸æ¸øÖÎÀíÔ±µÄÓʼþµØµã MailTo = admin@example.com # Æô¶¯logwatchЧÀÍ sudo logwatch
µÇ¼ºó¸´ÖÆ
ͨ¹ýʹÓÃÕâЩÏÂÁîÐй¤¾ß£¬ÎÒÃÇ¿ÉÒÔ´ó´óÌá¸ßЧÀÍÆ÷µÄÇå¾²ÐÔ¡£È»¶ø£¬ÎªÁËÈ·±£Ð§ÀÍÆ÷µÄÇå¾²£¬ÎÒÃÇ»¹Ó¦¸Ã°´ÆÚ¸üÐÂЧÀÍÆ÷µÄ²Ù×÷ϵͳºÍÈí¼þ£¬ÉèÖÃÇ¿ÃÜÂëÕ½ÂÔ£¬ÏÞÖÆÔ¶³Ì»á¼ûµÈ¡£Ö»ÓÐ×ÛºÏÔËÓÃÖÖÖÖÇå¾²²½·¥£¬ÎÒÃDzŻªÓÐÓõر£»¤Ð§ÀÍÆ÷ÃâÊܹ¥»÷µÄÍþв¡£
×ܽáÆðÀ´£¬ÏÂÁîÐй¤¾ßÊÇÌá¸ßЧÀÍÆ÷Çå¾²ÐÔµÄÖ÷Òª¹¤¾ßÖ®Ò»¡£ÎÞÂÛÊDZÜÃⱩÁ¦Æƽ⡢ÉèÖ÷À»ðǽ¹æÔòÕÕ¾ÉÆÊÎöÈÕÖ¾£¬ÏÂÁîÐй¤¾ß¶¼ÄÜ×ÊÖúÎÒÃǸüºÃµØ±£»¤Ð§ÀÍÆ÷µÄÇå¾²¡£Ï£Íû±¾ÎÄÌṩµÄʾÀý´úÂëÄܹ»×ÊÖú¶ÁÕ߸üºÃµØÃ÷È·ºÍʹÓÃÕâЩ¹¤¾ß£¬±£»¤×Ô¼ºµÄЧÀÍÆ÷ÃâÊܹ¥»÷¡£
ÒÔÉϾÍÊÇÏÂÁîÐй¤¾ß£ºÌá¸ßÄãµÄЧÀÍÆ÷Çå¾²ÐÔµÄÏêϸÄÚÈÝ£¬¸ü¶àÇë¹Ø×¢±¾ÍøÄÚÆäËüÏà¹ØÎÄÕ£¡