Running a security audit on your VPS Linux is essential after deploying a new server, and should be repeated periodically. This guide uses Lynis, the most popular open-source security auditing tool for Linux systems.
What is Lynis?
Lynis is an open-source security auditing tool for Unix/Linux that performs 300+ security checks covering OS hardening, file permissions, network configuration, authentication, logging, and more. It provides a Hardening Index score (0-100) with actionable suggestions.
Install Lynis
Method 1: Package Manager (Ubuntu/Debian)
sudo apt-get install lynis -y
Method 2: Download from GitHub (newer version)
cd /tmp curl -o lynis.tar.gz https://downloads.cisofy.com/lynis/lynis-3.1.3.tar.gz tar xfz lynis.tar.gz mv lynis /usr/local/lynis
Run a Security Audit
sudo lynis audit system
Lynis scans the entire system in 2-5 minutes. Results are shown in three categories:
- OK (green): Passed the check
- Warning (yellow): Should be fixed
- Suggestion (blue): Recommended improvement
The report ends with a Hardening Index such as Hardening index: 65 — aim for 70+.
View Detailed Lynis Results
sudo cat /var/log/lynis.log | grep "Warning\|Suggestion" | head -30
Understanding the Hardening Index and Score Ranges
The Hardening Index reflects your server's overall security posture. A higher score doesn't guarantee zero vulnerabilities, but indicates you've followed common hardening practices. Here's how to interpret the ranges:
| Index Range | Level | Meaning | Action |
|---|---|---|---|
| 0–49 | Weak | Fresh server or multiple critical issues found | Urgent fixes needed before going to production |
| 50–69 | Fair | Some hardening done, multiple warnings remain | Address warnings one by one |
| 70–84 | Good | Follows most best practices, suitable for production | Maintain and run audits regularly |
| 85–100 | Excellent | Comprehensively hardened, ideal for high-security servers | Audit every 3 months to maintain posture |
Remember that a high Hardening Index does not guarantee complete security. Application-level vulnerabilities and zero-day exploits are outside Lynis's scope, so pair it with other security tools.
Common Fixes
1. SSH Hardening
# Edit /etc/ssh/sshd_config PermitRootLogin no PasswordAuthentication no Protocol 2 MaxAuthTries 3
2. Disable Unused Services
sudo systemctl disable avahi-daemon sudo systemctl disable cups
3. sysctl Hardening
# Add to /etc/sysctl.conf net.ipv4.conf.all.rp_filter = 1 net.ipv4.tcp_syncookies = 1 kernel.dmesg_restrict = 1
Advanced Auditd Rules for Detailed Monitoring
Beyond basic Auditd installation, adding audit rules lets you capture specific high-value events such as modifications to critical configuration files, sudo usage, user account changes, and access to sensitive directories. This gives you an immutable audit trail for forensic investigation.
# List existing audit rules sudo auditctl -l # Watch /etc/passwd and /etc/shadow for write/attribute changes sudo auditctl -w /etc/passwd -p wa -k passwd_changes sudo auditctl -w /etc/shadow -p wa -k shadow_changes # Track sudo command executions sudo auditctl -a always,exit -F arch=b64 -S execve -F euid=0 -k sudo_commands # Save rules permanently sudo nano /etc/audit/rules.d/hardening.rules
Recommended hardening.rules content:
# Monitor sensitive configuration files -w /etc/passwd -p wa -k passwd_changes -w /etc/shadow -p wa -k shadow_changes -w /etc/sudoers -p wa -k sudoers_changes -w /etc/ssh/sshd_config -p wa -k sshd_config -w /var/log/auth.log -p wa -k auth_log # Track privileged command execution -a always,exit -F arch=b64 -S execve -F euid=0 -k privileged_exec
Reload Auditd after adding rules:
sudo systemctl restart auditd # Verify rules are loaded sudo auditctl -l
Search audit events by key:
# Find passwd change events sudo ausearch -k passwd_changes -i # View daily audit summary report sudo aureport --summary
Additional Security Hardening Tools to Use with Lynis
Lynis identifies problems but doesn't fix them automatically. These complementary tools help you build a layered security posture on your VPS:
- Fail2Ban: Bans IPs automatically after repeated failed login attempts. Supports SSH, Nginx, Apache, and many other services.
- UFW (Uncomplicated Firewall): Simplifies iptables management — open only necessary ports and deny everything else.
- rkhunter: Scans for rootkits and backdoors installed on the system.
- chkrootkit: An alternative rootkit scanner that works well alongside rkhunter.
- AIDE (Advanced Intrusion Detection Environment): Detects file system changes by comparing against a known-good baseline.
- ClamAV: Linux antivirus — scan uploaded files or run periodic directory scans.
Install and run rkhunter for rootkit detection:
sudo apt-get install rkhunter -y sudo rkhunter --update sudo rkhunter --check --sk
Note: many rkhunter WARNINGs are false positives from normal system customisation. Always review context before acting on results.
| Tool | Type | Purpose | Free |
|---|---|---|---|
| Lynis | Security Auditor | Full system hardening assessment | Yes |
| Auditd | System Logging | Real-time system call and file access logging | Yes |
| Fail2Ban | Intrusion Prevention | Automatic IP banning for brute force | Yes |
| rkhunter | Rootkit Scanner | Detect rootkits and backdoors | Yes |
| AIDE | File Integrity | Detect unauthorised file system changes | Yes |
Automating Security Monitoring and Alerts
Manual audits alone are insufficient for production servers. Set up automated alerting so you know when something changes. The simplest approach is a weekly cron job that runs Lynis and logs results via syslog, combined with Auditd forwarding to a centralised log system.
Schedule a weekly Lynis scan:
# Open crontab sudo crontab -e # Run Lynis every Sunday at 02:00 and log output 0 2 * * 0 /usr/bin/lynis audit system --quiet 2>&1 | /usr/bin/logger -t lynis-weekly
Review the weekly log via journal:
sudo journalctl -t lynis-weekly --since "7 days ago"
For Auditd, configure log rotation to preserve history in /etc/audit/auditd.conf:
# /etc/audit/auditd.conf log_format = ENRICHED num_logs = 10 max_log_file = 100 max_log_file_action = ROTATE
Beyond logging, define a clear incident response plan: when Lynis finds a new Warning or Auditd logs a suspicious event, know exactly who to notify, how to isolate the server if needed, and where backups are stored. Regular drills ensure your team can act quickly when a real incident occurs.
Install Auditd for System Call Logging
sudo apt-get install auditd -y sudo systemctl enable auditd && sudo systemctl start auditd
View audit logs:
sudo ausearch -ts recent -i | head -50
Recommendation: Run Lynis every 1-3 months or after installing new software. Aim for a Hardening Index above 70 and address all Warnings before they accumulate.
VPS Linux Ready to Deploy and Secure
AsiaGB VPS in Thailand and Singapore — Full Root Access to configure security your way. Plans from 500 THB/month.
View VPS Plans