ตรวจสอบความปลอดภัย VPS Linux Lynis Auditd

การทำ Security Audit บน VPS Linux เป็นสิ่งสำคัญที่ควรทำหลังจาก deploy server ใหม่ และควรทำซ้ำเป็นระยะ บทความนี้จะใช้ Lynis ซึ่งเป็น open-source security auditing tool ที่ได้รับความนิยมสูงสุดสำหรับ Linux

Lynis คืออะไร

Lynis เป็น open-source security auditing tool สำหรับ Unix/Linux ที่ตรวจสอบกว่า 300 security checks ครอบคลุม OS hardening, file permissions, network configuration, authentication, logging และอื่นๆ ให้คะแนน Hardening Index (0-100) พร้อม suggestions

ติดตั้ง Lynis

วิธีที่ 1: ผ่าน Package Manager (Ubuntu/Debian)

sudo apt-get install lynis -y

วิธีที่ 2: ดาวน์โหลดจาก GitHub (เวอร์ชันใหม่กว่า)

cd /tmp
curl -o lynis.tar.gz https://downloads.cisofy.com/lynis/lynis-3.1.3.tar.gz
tar xfz lynis.tar.gz
mv lynis /usr/local/lynis

รัน Security Audit

sudo lynis audit system

Lynis จะสแกนระบบทั้งหมดใช้เวลาประมาณ 2-5 นาที ผลลัพธ์จะแสดงใน 3 ส่วน:

ท้าย report จะมี Hardening Index เช่น Hardening index: 65 [############# ] — เป้าหมายควรได้มากกว่า 70

ดูผล Lynis แบบละเอียด

sudo cat /var/log/lynis.log | grep "Warning\|Suggestion" | head -30

หรือดูเฉพาะ warnings:

sudo lynis audit system --tests-from-group authentication,networking,filesystems

ทำความเข้าใจ Hardening Index และเกณฑ์คะแนน

Hardening Index ที่ Lynis ให้มาสะท้อนถึงระดับความปลอดภัยโดยรวมของ server คะแนนสูงไม่ได้แปลว่า server ไม่มีช่องโหว่เลย แต่แสดงว่ามีการ hardening ตามมาตรฐานทั่วไปในระดับดี การตีความคะแนนแบ่งออกเป็นช่วงดังนี้

Hardening Index ระดับ ความหมาย แนะนำ
0–49 อ่อนแอมาก Server ใหม่ที่ยังไม่ได้ hardening หรือมีช่องโหว่หลายจุด ต้องแก้ไขทันที ก่อน production
50–69 พอใช้ มีการ hardening บ้าง แต่ยังมี Warning หลายรายการ แก้ Warning ทีละรายการ
70–84 ดี ปฏิบัติตาม best practice ส่วนใหญ่ เหมาะกับ production ดูแลรักษาและรัน audit สม่ำเสมอ
85–100 ดีเยี่ยม Hardened อย่างครอบคลุม เหมาะกับ server ที่ต้องการความปลอดภัยสูง ทำ audit ทุก 3 เดือนเพื่อรักษาระดับ

โปรดทราบว่า Hardening Index ที่สูงไม่ได้รับประกันว่าจะปลอดภัย 100% เพราะยังมีปัจจัยด้าน application-level vulnerabilities และ zero-day exploits ที่ Lynis ไม่สามารถตรวจพบได้

การแก้ไขที่พบบ่อย

1. SSH Hardening

# แก้ /etc/ssh/sshd_config
PermitRootLogin no
PasswordAuthentication no
Protocol 2
MaxAuthTries 3

2. ปิด Service ที่ไม่ใช้

sudo systemctl disable avahi-daemon
sudo systemctl disable cups

3. ตั้งค่า sysctl hardening

# เพิ่มใน /etc/sysctl.conf
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
net.ipv4.tcp_syncookies = 1
kernel.dmesg_restrict = 1

การตั้งค่า Auditd Rules สำหรับ Monitoring ที่ละเอียดขึ้น

นอกจากการติดตั้ง Auditd พื้นฐานแล้ว การเพิ่ม audit rules จะช่วยให้ระบบบันทึก event ที่สำคัญได้ละเอียดยิ่งขึ้น เช่น การแก้ไขไฟล์ configuration ที่สำคัญ การใช้ sudo การเปลี่ยนแปลง user accounts และการเข้าถึงไฟล์ที่มีความอ่อนไหว

# ดู audit rules ที่มีอยู่
sudo auditctl -l

# เพิ่ม rule ตรวจจับการแก้ไข /etc/passwd และ /etc/shadow
sudo auditctl -w /etc/passwd -p wa -k passwd_changes
sudo auditctl -w /etc/shadow -p wa -k shadow_changes

# ตรวจจับการใช้ sudo
sudo auditctl -a always,exit -F arch=b64 -S execve -F euid=0 -k sudo_commands

# บันทึก rule ให้ถาวร
sudo nano /etc/audit/rules.d/hardening.rules

เนื้อหาไฟล์ hardening.rules ที่แนะนำ:

# Monitor sensitive files
-w /etc/passwd -p wa -k passwd_changes
-w /etc/shadow -p wa -k shadow_changes
-w /etc/sudoers -p wa -k sudoers_changes
-w /etc/ssh/sshd_config -p wa -k sshd_config
-w /var/log/auth.log -p wa -k auth_log

# Monitor privileged commands
-a always,exit -F arch=b64 -S execve -F euid=0 -k privileged_exec

หลังเพิ่ม rules แล้วต้อง reload:

sudo systemctl restart auditd
# ตรวจสอบ rules ที่โหลดแล้ว
sudo auditctl -l

การค้นหา audit events ที่เกี่ยวกับ key ที่ตั้งไว้:

# ดู event ที่เกี่ยวกับ passwd_changes
sudo ausearch -k passwd_changes -i

# สรุป audit รายวัน
sudo aureport --summary

เครื่องมือ Security Hardening เพิ่มเติมที่ใช้คู่กับ Lynis

Lynis บอกว่ามีปัญหาอะไร แต่ไม่ได้แก้ให้อัตโนมัติ มีเครื่องมืออื่นที่ช่วยทำ hardening ได้เพิ่มเติม ดังนี้

ติดตั้งและรัน rkhunter สำหรับตรวจ rootkit:

sudo apt-get install rkhunter -y
sudo rkhunter --update
sudo rkhunter --check --sk

ผล WARNING จาก rkhunter ส่วนใหญ่เป็น false positive จากการปรับแต่ง system ปกติ ให้ดูบริบทก่อนตัดสินใจ

เครื่องมือ ประเภท ใช้งาน ฟรี
Lynis Security Auditor ตรวจสถานะ hardening ทั้งหมด ใช่
Auditd System Logging บันทึก system call และ file access ใช่
Fail2Ban Intrusion Prevention Ban IP brute force อัตโนมัติ ใช่
rkhunter Rootkit Scanner ตรวจ rootkit และ backdoor ใช่
AIDE File Integrity ตรวจการเปลี่ยนแปลงไฟล์ ใช่

แนวทาง Automated Security Monitoring และการแจ้งเตือน

การรัน audit ด้วยมือนั้นไม่เพียงพอสำหรับ server ที่ใช้งานจริง ควรตั้งระบบแจ้งเตือนอัตโนมัติเมื่อเกิด event สำคัญ วิธีง่ายที่สุดคือใช้ cron job ส่ง Lynis report ทางอีเมล และตั้ง Auditd alert ผ่าน syslog

ตั้ง cron job รัน Lynis สัปดาห์ละครั้งและบันทึกผล:

# เปิด crontab
sudo crontab -e

# รัน Lynis ทุกวันอาทิตย์ 02:00 น. และบันทึกผล
0 2 * * 0 /usr/bin/lynis audit system --quiet 2>&1 | /usr/bin/logger -t lynis-weekly

ตรวจสอบ Lynis log ผ่าน systemd journal:

sudo journalctl -t lynis-weekly --since "7 days ago"

สำหรับ Auditd ให้ตั้ง syslog output เพื่อส่ง log ไปยัง centralized logging system เช่น Graylog หรือ Elasticsearch แก้ไขไฟล์ /etc/audit/auditd.conf:

# ใน /etc/audit/auditd.conf
log_format = ENRICHED
log_file = /var/log/audit/audit.log
num_logs = 10
max_log_file = 100
max_log_file_action = ROTATE

นอกจากนี้ยังสามารถใช้บริการ monitoring ภายนอกเช่น Uptime Kuma หรือ Grafana เพื่อสร้าง dashboard แสดง security metrics ของ server แบบ real-time ได้ด้วย

สิ่งสำคัญที่สุดคือการมี incident response plan: รู้ว่าเมื่อ Lynis พบ Warning หรือ Auditd พบ event ผิดปกติจะทำอะไรก่อน เช่น ตรวจสอบ log, isolate server, backup data และแจ้งทีมที่เกี่ยวข้อง การซ้อม drill สม่ำเสมอจะช่วยให้แน่ใจว่าทุกคนรู้ขั้นตอน

ติดตั้ง Auditd สำหรับ System Call Logging

sudo apt-get install auditd -y
sudo systemctl enable auditd && sudo systemctl start auditd

ดู audit log:

sudo ausearch -ts recent -i | head -50

แนวทางปฏิบัติที่ดีที่สุดสำหรับ VPS Security ในระยะยาว

การทำ security audit เพียงครั้งเดียวไม่เพียงพอ ความปลอดภัยของ VPS ต้องอาศัยการดูแลต่อเนื่องและเป็นระบบ ต่อไปนี้คือ checklist ที่ควรทำสม่ำเสมอเพื่อรักษาระดับความปลอดภัยที่ดี

รายวัน (อัตโนมัติ)

รายสัปดาห์

รายเดือน

รายไตรมาส

การทำ security hardening บน VPS เป็นกระบวนการต่อเนื่อง ภัยคุกคามใหม่ๆ เกิดขึ้นตลอดเวลา การติดตาม security advisories จาก Ubuntu Security Notices (ubuntu.com/security/notices) และ Debian Security (security.debian.org) ช่วยให้รู้ว่ามี vulnerability ใหม่ที่ต้องแพทช์เมื่อไร

สิ่งสำคัญอีกประการคือ ห้ามรัน production workload ในฐานะ root ให้สร้าง user แยกสำหรับแต่ละ application และให้สิทธิ์เฉพาะที่จำเป็น (Principle of Least Privilege) การทำแบบนี้จะจำกัดความเสียหายหาก application ถูก exploit ได้

ตั้งค่า Unattended Upgrades สำหรับ Security Patch อัตโนมัติ

การอัปเดต security patch ด้วยมือมักทำได้ไม่สม่ำเสมอ Ubuntu รองรับ unattended-upgrades ที่ติดตั้ง security patch อัตโนมัติโดยไม่ต้อง reboot (ยกเว้น kernel update)

sudo apt-get install unattended-upgrades -y
sudo dpkg-reconfigure -plow unattended-upgrades

ตรวจสอบว่า unattended-upgrades ทำงาน:

sudo systemctl status unattended-upgrades
# ดู log การอัปเดต
sudo cat /var/log/unattended-upgrades/unattended-upgrades.log | tail -30

การตั้งค่านี้จะดาวน์โหลดและติดตั้งเฉพาะ security updates อัตโนมัติ ส่วน general updates ยังคงต้องทำด้วยมือ ซึ่งเป็นแนวปฏิบัติที่ดีเพราะ general updates อาจมีการเปลี่ยนแปลงที่กระทบ compatibility ของ application

ป้องกัน Brute Force ด้วย SSH Rate Limiting

นอกจาก Fail2Ban แล้ว สามารถเพิ่ม rate limiting สำหรับ SSH ผ่าน UFW โดยตรงเพื่อป้องกัน brute force ในชั้น firewall ก่อนที่ connection จะถึง SSH daemon

# จำกัดการเชื่อมต่อ SSH ไม่เกิน 6 ครั้งใน 30 วินาที
sudo ufw limit ssh

# ตรวจสอบ rule ที่เพิ่ม
sudo ufw status verbose

วิธีนี้ช่วยลด load บน server ระหว่างถูก scan และทำให้ Fail2Ban ทำงานมีประสิทธิภาพมากขึ้น เนื่องจากกรองการเชื่อมต่อที่เร็วผิดปกติออกตั้งแต่ต้น

แนะนำ: รัน Lynis ทุก 1-3 เดือน หรือหลังติดตั้ง software ใหม่ เป้าหมาย Hardening Index > 70 และแก้ไข Warning ทั้งหมดก่อน Warning ถัดไปสะสม

VPS Linux พร้อม Deploy และ Secure

AsiaGB VPS ไทยและสิงคโปร์ — Full Root Access ตั้งค่า Security ได้ตามต้องการ เริ่มต้น 500 บาท/เดือน

ดู VPS Plans