Harden linux workstation suggestions

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












I'm planning to switch for ever to linux - archlinux:



I implemented nft firewall to block all input comming to the box, no port expose, no daemon listening on a port.



further I'm considering to use linux-harden kernel instead of linux one, but really don't like this idea because I want to know what patches need to apply for my system, this also bad idea because it can burden my daily use and reduce productivity.



I'm thinking about something that check integrity of the box in real time - like antivirus on windows but don't know what to use here? Do you have suggestions?



I also need something to regularly scan and check vulnerabilities on the box so I can close it asap.



Is there any that you can suggest to harden my further box?



Thanks in advanced. Hope this is in the right forum.









share























  • Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
    – jasonwryan
    3 mins ago














up vote
0
down vote

favorite












I'm planning to switch for ever to linux - archlinux:



I implemented nft firewall to block all input comming to the box, no port expose, no daemon listening on a port.



further I'm considering to use linux-harden kernel instead of linux one, but really don't like this idea because I want to know what patches need to apply for my system, this also bad idea because it can burden my daily use and reduce productivity.



I'm thinking about something that check integrity of the box in real time - like antivirus on windows but don't know what to use here? Do you have suggestions?



I also need something to regularly scan and check vulnerabilities on the box so I can close it asap.



Is there any that you can suggest to harden my further box?



Thanks in advanced. Hope this is in the right forum.









share























  • Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
    – jasonwryan
    3 mins ago












up vote
0
down vote

favorite









up vote
0
down vote

favorite











I'm planning to switch for ever to linux - archlinux:



I implemented nft firewall to block all input comming to the box, no port expose, no daemon listening on a port.



further I'm considering to use linux-harden kernel instead of linux one, but really don't like this idea because I want to know what patches need to apply for my system, this also bad idea because it can burden my daily use and reduce productivity.



I'm thinking about something that check integrity of the box in real time - like antivirus on windows but don't know what to use here? Do you have suggestions?



I also need something to regularly scan and check vulnerabilities on the box so I can close it asap.



Is there any that you can suggest to harden my further box?



Thanks in advanced. Hope this is in the right forum.









share















I'm planning to switch for ever to linux - archlinux:



I implemented nft firewall to block all input comming to the box, no port expose, no daemon listening on a port.



further I'm considering to use linux-harden kernel instead of linux one, but really don't like this idea because I want to know what patches need to apply for my system, this also bad idea because it can burden my daily use and reduce productivity.



I'm thinking about something that check integrity of the box in real time - like antivirus on windows but don't know what to use here? Do you have suggestions?



I also need something to regularly scan and check vulnerabilities on the box so I can close it asap.



Is there any that you can suggest to harden my further box?



Thanks in advanced. Hope this is in the right forum.







security hardening





share














share












share



share








edited 4 mins ago









jasonwryan

48.3k14133182




48.3k14133182










asked 8 mins ago









Tuyen Pham

397111




397111











  • Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
    – jasonwryan
    3 mins ago
















  • Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
    – jasonwryan
    3 mins ago















Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
– jasonwryan
3 mins ago




Did you read the link I posted to your earlier closed question? The Arch Wiki has a page specifically on this.
– jasonwryan
3 mins ago















active

oldest

votes











Your Answer








StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480681%2fharden-linux-workstation-suggestions%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f480681%2fharden-linux-workstation-suggestions%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

How to check contact read email or not when send email to Individual?

Bahrain

Postfix configuration issue with fips on centos 7; mailgun relay