服务器是数字世界的核心基础设施,其稳定运作直接影响业务连续性,本文基于NIST SP 800-123网络安全框架与Linux基金会运维标准,为技术人员提供可落地的生存指南。
sudo apt install unattended-upgrades sudo dpkg-reconfigure --priority=low unattended-upgrades
GRUB_DEFAULT=saved
保留启动选项ss -tulwn
审查开放端口systemctl mask [service-name]
Port 49231
chmod 700 ~/.ssh chmod 600 ~/.ssh/authorized_keys
iptables -A INPUT -p tcp --dport 49231 -j ACCEPT iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -P INPUT DROP
server_tokens off;
add_header Strict-Transport-Security "max-age=63072000" always;
CREATE USER 'appuser'@'localhost' IDENTIFIED BY 'StrongP@ssw0rd!2023'; REVOKE ALL PRIVILEGES ON *.* FROM 'appuser'@'localhost'; GRANT SELECT, INSERT ON mydb.* TO 'appuser'@'localhost';
rkhunter --check --sk
lvcreate --size 10G --snapshot --name snap_202308 /dev/vg00/lvol0
load5 > 0.7 * CPU核心数
80%
df -i
log_format main '$remote_addr - $remote_user [$time_local] ' '"$request" $status $body_bytes_sent ' '"$http_referer" "$http_user_agent"';
所需容量 = 当前用量 × (1 + 月增长率)^6 + 安全余量(20%)
auditctl -a always,exit -F arch=b64 -S open -S creat -F key=file_access
%webadmins ALL=(root) NOPASSWD: /usr/bin/systemctl reload nginx
visudo -c && grep -Po '^[^#]w+' /etc/sudoers
引用说明
[1] NIST Special Publication 800-123 网络安全指南
[2] Linux Foundation 系统运维最佳实践
[3] AWS Well-Architected Framework 架构白皮书
[4] OWASP Web应用安全标准 V4.0