Penerapan Hardening Server Linux untuk Meningkatkan Keamanan Sistem Messaging IoT 433 532
DOI:
https://doi.org/10.26623/transformatika.v23i2.13776Keywords:
Pengerasan Server, Keamanan Sistem, IoT, Firewall, SSHAbstract
Linux-based servers are extensively utilized as core infrastructure for network services, particularly as IoT Messaging Servers based on the MQTT protocol. However, many servers remain vulnerable to security breaches due to misconfigurations or unpatched flaws. This study aims to implement and analyze the effectiveness of Linux server hardening in enhancing system security against network-based attacks. The research was conducted using Ubuntu Server 22.04 running Mosquitto MQTT within a virtualized environment, employing a limited penetration testing approach. Testing scenarios were focused on port scanning, brute-force authentication attacks, and unauthorized access to MQTT services, excluding kernel-level or zero-day exploits. The hardening methodology encompasses system updates, SSH configuration hardening, user management, UFW firewall implementation, Fail2ban integration, Mosquitto-specific hardening, and security log monitoring. Security indicators were measured based on the reduction of open ports, the success rate of automated brute-force blocking, and the improvement in logging quality. The results demonstrate a reduction in vulnerability exposure by up to 75% and a significant improvement in security detection and response. This research contributes a novel measurable integration between hardening automation, firewalling, and IoT applications, thereby minimizing the risk of exploitation vulnerabilities.
Downloads
References
[1] Ansar SH, Sadiq A, Ihsan U, Ashraf H, Somantri. Fortifying Linux Server and Implementing a Zero Trust Network Access (ZTNA) for Enhanced Security. Engineering Proceedings. 2025; 107(1): 99.
[2] Niu S, Mo J, Zhang Z, Lv Z. Overview of Linux vulnerabilities. International Conference on Soft Computing in Information Communication Technology (SCICT). 2014.
[3] Ayyoub B. Enhance Linux server security: common misconfigurations and vulnerabilities. International Journal of Secure Systems and Networks. 2022; 10(3): 45–59.
[4] Sri Hari Aravindan S. A Review of Linux System Hardening Techniques for Enterprise Security and Compliance. International Journal of Scientific Engineering and Research (IJSER). 2025; 13(10).
[5] Irawan B, Sheha KN, Rahaman M, Erzed N, Herwanto A. Evaluating the Effectiveness of Center for Internet Security (CIS) Benchmark for Hardening Ubuntu Server 22.04 Against Cyber Threats. International Journal of Scientific Research (IJSR). 2025; 14(6): doi: 10.55324/josr.v4i6.2544.
[6] Chen H, Han X, Zhang Y. Endogenous Security Formal Definition, Innovation Mechanisms, and Experiment Research in Industrial Internet. Tsinghua Science and Technology. 2023; 29(2): 492–505. doi: 10.26599/TST.2023.9010034.
[7] Almaiah MA, et al. Classification of Cybersecurity Threats, Vulnerabilities and Countermeasures in Database Systems. Computers, Materials & Continua. 2024; 77(3): 6845–6869. doi: 10.32604/cmc.2024.057673.
[8] Bhurtel S. Unveiling the Landscape of Operating System Vulnerabilities. Future Internet. 2023; 15(7): 248.
[9] Alhamed M, Albahrani I, et al. A Systematic Literature Review on Penetration Testing in Networks. Applied Sciences. 2023; 13(12): 6986. doi: 10.3390/app13126986.
[10] Alhamed M, Albahrani I, et al. A Systematic Literature Review on Penetration Testing in Networks. Applied Sciences. 2023; 13(12): 6986. doi: 10.3390/app13126986.
[11] Abu Bakar R, Kijsirikul B. Enhancing Network Visibility and Security with Advanced Port Scanning Techniques. Sensors. 2023; 23(17): art. 7541. doi: 10.3390/s23177541.
[12] Park J, Yim K, Choi S, Kim G, Lee Y. Network Log-Based SSH Brute-Force Attack Detection Model. Journal of Network and Computer Applications. 2021; 186: 103063.
[13] Ruambo FA, Ruambo MM, Dandalo DT, Makwembere K. Brute-force attack mitigation on remote access services via a zero-trust-aligned software-defined perimeter. Scientific Reports. 2025; 15: art. no. 10805. doi: 10.1038/s41598-025-01080-5.
[14] Landauer M, Onder S, Skopik F, Wurzenberger M. Deep learning for anomaly detection in log data: A survey. Machine Learning with Applications. 2023; 13: 100470. doi: 10.1016/j.mlwa.2023.100470.
[15] Park J, Kim JS, Gupta BB, Park N. Network Log-Based SSH Brute-Force Attack Detection Model. Computers, Materials & Continua. 2021; 68(1): 888–901. doi: 10.32604/cmc.2021.015172.6
[16] Bangare PS, Patil KP. Enhancing MQTT security for Internet of Things: Lightweight two-way authorization and authentication with advanced security measures. Measurement: Sensors. 2024; 78: 100250. doi: 10.1016/j.measurements.2023.100250.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Agus Hartanto, Lenny Margaretta Huizen, April Firmandaru, surono surono

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.

Transformatika is licensed under a Creative Commons Attribution 4.0 International License.



