<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=UBUNTU_-_Hardening</id>
	<title>UBUNTU - Hardening - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=UBUNTU_-_Hardening"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=UBUNTU_-_Hardening&amp;action=history"/>
	<updated>2026-05-02T18:47:50Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=UBUNTU_-_Hardening&amp;diff=1061&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=UBUNTU_-_Hardening&amp;diff=1061&amp;oldid=prev"/>
		<updated>2026-01-17T08:52:34Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:52, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scope and Threat Model ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Scope and Threat Model ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=UBUNTU_-_Hardening&amp;diff=720&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Scope and Threat Model ==  This hardening post-install script is designed to reduce the attack surface of a freshly installed Ubuntu system (server or workstation) by enforcing secure defaults, disabling unnecessary components, and applying defense-in-depth controls.  The threat model assumes: * Remote network-based attacks * Local privilege escalation attempts * Misconfiguration exploitation * Persistence via services, cron jobs, or kernel paramete...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=UBUNTU_-_Hardening&amp;diff=720&amp;oldid=prev"/>
		<updated>2025-12-20T16:47:57Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Scope and Threat Model ==  This hardening post-install script is designed to reduce the attack surface of a freshly installed Ubuntu system (server or workstation) by enforcing secure defaults, disabling unnecessary components, and applying defense-in-depth controls.  The threat model assumes: * Remote network-based attacks * Local privilege escalation attempts * Misconfiguration exploitation * Persistence via services, cron jobs, or kernel paramete...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Scope and Threat Model ==&lt;br /&gt;
&lt;br /&gt;
This hardening post-install script is designed to reduce the attack surface of a freshly installed Ubuntu system (server or workstation) by enforcing secure defaults, disabling unnecessary components, and applying defense-in-depth controls.&lt;br /&gt;
&lt;br /&gt;
The threat model assumes:&lt;br /&gt;
* Remote network-based attacks&lt;br /&gt;
* Local privilege escalation attempts&lt;br /&gt;
* Misconfiguration exploitation&lt;br /&gt;
* Persistence via services, cron jobs, or kernel parameters&lt;br /&gt;
* Credential brute-force and reuse attacks&lt;br /&gt;
&lt;br /&gt;
== Security Principles Applied ==&lt;br /&gt;
&lt;br /&gt;
=== Least Privilege ===&lt;br /&gt;
Users, services, and applications are granted only the minimal permissions required.&lt;br /&gt;
&lt;br /&gt;
=== Defense in Depth ===&lt;br /&gt;
Multiple layers of security controls are applied (firewall, kernel hardening, MAC, auditing).&lt;br /&gt;
&lt;br /&gt;
=== Secure by Default ===&lt;br /&gt;
Insecure defaults are replaced with hardened configurations immediately after installation.&lt;br /&gt;
&lt;br /&gt;
=== Auditable and Reversible ===&lt;br /&gt;
All changes are logged and configuration backups are created before modification.&lt;br /&gt;
&lt;br /&gt;
== Script Architecture ==&lt;br /&gt;
&lt;br /&gt;
The hardening script is modular and idempotent.&lt;br /&gt;
&lt;br /&gt;
Recommended structure:&lt;br /&gt;
* 00-preflight.sh&lt;br /&gt;
* 10-system-updates.sh&lt;br /&gt;
* 20-user-and-auth.sh&lt;br /&gt;
* 30-ssh-hardening.sh&lt;br /&gt;
* 40-firewall.sh&lt;br /&gt;
* 50-kernel-hardening.sh&lt;br /&gt;
* 60-filesystem.sh&lt;br /&gt;
* 70-auditing.sh&lt;br /&gt;
* 80-mandatory-access-control.sh&lt;br /&gt;
* 90-services-cleanup.sh&lt;br /&gt;
&lt;br /&gt;
Each module:&lt;br /&gt;
* Verifies prerequisites&lt;br /&gt;
* Applies configuration&lt;br /&gt;
* Validates results&lt;br /&gt;
* Logs changes&lt;br /&gt;
&lt;br /&gt;
Example dispatcher:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
for module in modules/*.sh; do&lt;br /&gt;
    bash &amp;quot;$module&amp;quot;&lt;br /&gt;
done&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== System Update and Package Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== Automatic Security Updates ===&lt;br /&gt;
&lt;br /&gt;
Enable unattended upgrades for security patches:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt install -y unattended-upgrades&lt;br /&gt;
dpkg-reconfigure --priority=low unattended-upgrades&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Vulnerability window reduction*&lt;br /&gt;
&lt;br /&gt;
=== Package Minimization ===&lt;br /&gt;
&lt;br /&gt;
Remove unnecessary packages:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt purge -y telnet ftp rsh-server xinetd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Disable unused package managers:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chmod -x /usr/bin/snap&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== User Accounts and Authentication ==&lt;br /&gt;
&lt;br /&gt;
=== Password Policy ===&lt;br /&gt;
&lt;br /&gt;
Configure PAM password quality:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt install -y libpam-pwquality&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example `/etc/security/pwquality.conf` settings:&lt;br /&gt;
* minlen = 14&lt;br /&gt;
* retry = 3&lt;br /&gt;
* enforce_for_root&lt;br /&gt;
&lt;br /&gt;
=== Account Lockout ===&lt;br /&gt;
&lt;br /&gt;
Mitigate brute-force attacks:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
pam_tally2 --user testuser&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Credential attack mitigation*&lt;br /&gt;
&lt;br /&gt;
=== Disable Root Login ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
passwd -l root&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== SSH Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== Secure SSH Configuration ===&lt;br /&gt;
&lt;br /&gt;
Example hardened settings in `/etc/ssh/sshd_config`:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
PermitRootLogin no&lt;br /&gt;
PasswordAuthentication no&lt;br /&gt;
X11Forwarding no&lt;br /&gt;
AllowTcpForwarding no&lt;br /&gt;
MaxAuthTries 3&lt;br /&gt;
ClientAliveInterval 300&lt;br /&gt;
ClientAliveCountMax 0&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Restart service:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
systemctl restart ssh&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concepts:&lt;br /&gt;
* Attack surface reduction&lt;br /&gt;
* Strong authentication enforcement&lt;br /&gt;
&lt;br /&gt;
== Firewall and Network Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== UFW Configuration ===&lt;br /&gt;
&lt;br /&gt;
Default deny policy:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ufw default deny incoming&lt;br /&gt;
ufw default allow outgoing&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Allow required services only:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ufw allow 22/tcp&lt;br /&gt;
ufw enable&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Kernel Network Parameters ===&lt;br /&gt;
&lt;br /&gt;
Example sysctl hardening:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
net.ipv4.conf.all.rp_filter=1&lt;br /&gt;
net.ipv4.tcp_syncookies=1&lt;br /&gt;
net.ipv4.icmp_echo_ignore_broadcasts=1&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Apply:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
sysctl -p&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Network-level attack mitigation*&lt;br /&gt;
&lt;br /&gt;
== Kernel and Memory Hardening ==&lt;br /&gt;
&lt;br /&gt;
=== Address Space Layout Randomization ===&lt;br /&gt;
&lt;br /&gt;
Verify ASLR:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
cat /proc/sys/kernel/randomize_va_space&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Expected value: `2`&lt;br /&gt;
&lt;br /&gt;
=== Restrict Kernel Information ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
kernel.kptr_restrict=2&lt;br /&gt;
kernel.dmesg_restrict=1&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Information leakage prevention*&lt;br /&gt;
&lt;br /&gt;
== Filesystem and Mount Options ==&lt;br /&gt;
&lt;br /&gt;
=== Secure Mount Flags ===&lt;br /&gt;
&lt;br /&gt;
Example `/etc/fstab` entries:&lt;br /&gt;
* noexec&lt;br /&gt;
* nodev&lt;br /&gt;
* nosuid&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
tmpfs /tmp tmpfs defaults,noexec,nosuid,nodev 0 0&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== File Permission Auditing ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
find / -xdev -type f -perm -4000&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Privilege escalation prevention*&lt;br /&gt;
&lt;br /&gt;
== Auditing and Logging ==&lt;br /&gt;
&lt;br /&gt;
=== Auditd Configuration ===&lt;br /&gt;
&lt;br /&gt;
Install and enable:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
apt install -y auditd audispd-plugins&lt;br /&gt;
systemctl enable auditd&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Example rule:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
-w /etc/passwd -p wa -k identity&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Log Retention and Protection ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
chmod 600 /var/log/auth.log&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Forensic readiness*&lt;br /&gt;
&lt;br /&gt;
== Mandatory Access Control (AppArmor) ==&lt;br /&gt;
&lt;br /&gt;
=== Enforcing Mode ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aa-status&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Enable profiles:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aa-enforce /etc/apparmor.d/*&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Application-level isolation*&lt;br /&gt;
&lt;br /&gt;
== Service Hardening and Cleanup ==&lt;br /&gt;
&lt;br /&gt;
=== Disable Unused Services ===&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
systemctl disable avahi-daemon&lt;br /&gt;
systemctl disable cups&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
List listening services:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ss -tulpen&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Security concept: *Service exposure reduction*&lt;br /&gt;
&lt;br /&gt;
== Example Execution Output ==&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
[OK] Firewall enabled&lt;br /&gt;
[OK] SSH hardened&lt;br /&gt;
[WARN] AppArmor profile missing for custom app&lt;br /&gt;
[OK] Audit rules loaded&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
=== SSH Lockout ===&lt;br /&gt;
&lt;br /&gt;
**Symptom:** Cannot connect via SSH  &lt;br /&gt;
**Resolution:**&lt;br /&gt;
* Use console access&lt;br /&gt;
* Re-enable password authentication temporarily:&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
PasswordAuthentication yes&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Firewall Blocking Services ===&lt;br /&gt;
&lt;br /&gt;
**Symptom:** Service unreachable  &lt;br /&gt;
**Resolution:**&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ufw status verbose&lt;br /&gt;
ufw allow &amp;lt;port&amp;gt;/&amp;lt;protocol&amp;gt;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== System Boot Issues After Sysctl Changes ===&lt;br /&gt;
&lt;br /&gt;
**Symptom:** Boot hangs or networking fails  &lt;br /&gt;
**Resolution:**&lt;br /&gt;
* Boot into recovery mode&lt;br /&gt;
* Comment problematic entries in `/etc/sysctl.conf`&lt;br /&gt;
&lt;br /&gt;
=== Auditd Performance Impact ===&lt;br /&gt;
&lt;br /&gt;
**Symptom:** High I/O usage  &lt;br /&gt;
**Resolution:**&lt;br /&gt;
* Reduce audit rule verbosity&lt;br /&gt;
* Exclude high-frequency paths&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* https://ubuntu.com/security&lt;br /&gt;
* https://wiki.ubuntu.com/Security&lt;br /&gt;
* https://www.cisecurity.org/cis-benchmarks&lt;br /&gt;
* https://manpages.ubuntu.com&lt;br /&gt;
* https://owasp.org&lt;br /&gt;
* https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/security_hardening&lt;br /&gt;
* https://linux-audit.com&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>