[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Anti virus and Firewall



On Tue, Aug 03, 2010 at 10:43:05PM +0100, Tingez Unknown wrote:
>    I am looking for any suggestions regarding Anti virus and firewall
>    software that is suitable with your Debian 5 64bit operating system.
>    Wanting to add as much security as possible to our server to reduce any
>    problems we may encounter. I would like any suggestions as to the best
>    software that can be used either paid for or freeware if you would be so
>    kind.

While antivirus software exists for GNU/Linux systems such as Debian,
it's not really needed as most viruses are targeting Windows machines.
If you are concerned about the potential impact, I would recommend
running SELinux coupled with AIDE over any antivirus software. While
their goals are slightly different, the overall idea is the same- lock
down the server, and prevent any unouthorized changes to the filesystem.

When changes occur, report the change, and give an ability to restore
completely from backup. The best antivirus software will do for you is
report the virus, and attempt to remove the virus. Because you can never
be sure what has been changed, it's always best to do a reinstall after
an infection. You would do the same with SELinux and AIDE.

In terms of firewall, the Linux kernel has a builtin firewall through
the Netfilter module and the 'iptables' userspace command. There are
frontends for iptables, if it is too intimidating for you. There's also
TCP wrappers and xinetd for additional firewalling. You could even using
ACLs to allow and deny access to your services.

-- 
. O .   O . O   . . O   O . .   . O .
. . O   . O O   O . O   . O O   . . O
O O O   . O .   . O O   O O .   O O O

Attachment: signature.asc
Description: Digital signature


Reply to: