Methods for Enhancing Security in Linux Server Administration: A Study of Protection Practices in Server Management - Permission Configuration, Auditing, Two-Factor Authentication, SSH Access Control

Mihail Aleksandrovich Romanov, Anton Olegovich Badalin, Dmitrii Vital'evich Ribalka, Vitalii Valerievich Borisov, Dar'ya Dmitrievna Novikova · Программные системы и вычислительные методы · 2025

The subject of this research is practical methods and a comprehensive approach to enhancing security levels in the administration of servers running the Linux operating system. The study focuses on the analysis and practical implementation of key protective mechanisms that make up a multi-layered defense of server infrastructure. These include strict access rights management based on the principle of least privilege, which minimizes damage from potential account compromise. The enhancement of remote management security is also addressed, particularly the configuration of SSH access using cryptographic keys instead of passwords, and limiting the list of allowed users and network addresses. An important component of the subject is the implementation of two-factor authentication for critical operations, adding an additional barrier against intruders. Finally, the subject covers the organization of an audit and monitoring system to log and analyze system events, ensuring transparency of administrator actions and the ability to quickly identify security incidents. The methodology includes the practical implementation of security measures on a test Linux server: creating a three-tier user model, configuring SSH, and implementing 2FA. Effectiveness was tested through scenarios simulating privilege escalation attacks and unauthorized access. The scientific novelty of the work lies in the comprehensive, applied study of the relationship and synergistic effect from the combined application of several fundamental, yet critically important, protective measures in the context of real administration. Unlike theoretical overviews or studies of isolated tools, this article offers a holistic, step-by-step model for building defenses, validated through simulated attacks. A key conclusion is the demonstration that consistent and coherent application of fundamental principles—minimized privileges, enhanced authentication, and comprehensive auditing—creates a robust multi-layered security system capable of effectively countering standard attack vectors aimed at unauthorized rights acquisition. Results show that even without the use of complex, expensive solutions, proper basic configuration significantly raises the barrier to hacking and improves infrastructure manageability. The practical significance of the work lies in the development of a ready-made set of verified configurations and testing scenarios that can be directly used by system administrators to audit and strengthen existing servers.

Read the paper · More papers on PaperTik