Penerapan Hardening Server Linux untuk Meningkatkan Keamanan Sistem Messaging IoT 433 532

Authors

DOI:

https://doi.org/10.26623/transformatika.v23i2.13776

Keywords:

Pengerasan Server, Keamanan Sistem, IoT, Firewall, SSH

Abstract

Linux-based servers are extensively utilized as core infrastructure for network services, particularly as IoT Messaging Servers based on the MQTT protocol. However, many servers remain vulnerable to security breaches due to misconfigurations or unpatched flaws. This study aims to implement and analyze the effectiveness of Linux server hardening in enhancing system security against network-based attacks. The research was conducted using Ubuntu Server 22.04 running Mosquitto MQTT within a virtualized environment, employing a limited penetration testing approach. Testing scenarios were focused on port scanning, brute-force authentication attacks, and unauthorized access to MQTT services, excluding kernel-level or zero-day exploits. The hardening methodology encompasses system updates, SSH configuration hardening, user management, UFW firewall implementation, Fail2ban integration, Mosquitto-specific hardening, and security log monitoring. Security indicators were measured based on the reduction of open ports, the success rate of automated brute-force blocking, and the improvement in logging quality. The results demonstrate a reduction in vulnerability exposure by up to 75% and a significant improvement in security detection and response. This research contributes a novel measurable integration between hardening automation, firewalling, and IoT applications, thereby minimizing the risk of exploitation vulnerabilities.

Downloads

Download data is not yet available.

References

[1] Ansar SH, Sadiq A, Ihsan U, Ashraf H, Somantri. Fortifying Linux Server and Implementing a Zero Trust Network Access (ZTNA) for Enhanced Security. Engineering Proceedings. 2025; 107(1): 99.

[2] Niu S, Mo J, Zhang Z, Lv Z. Overview of Linux vulnerabilities. International Conference on Soft Computing in Information Communication Technology (SCICT). 2014.

[3] Ayyoub B. Enhance Linux server security: common misconfigurations and vulnerabilities. International Journal of Secure Systems and Networks. 2022; 10(3): 45–59.

[4] Sri Hari Aravindan S. A Review of Linux System Hardening Techniques for Enterprise Security and Compliance. International Journal of Scientific Engineering and Research (IJSER). 2025; 13(10).

[5] Irawan B, Sheha KN, Rahaman M, Erzed N, Herwanto A. Evaluating the Effectiveness of Center for Internet Security (CIS) Benchmark for Hardening Ubuntu Server 22.04 Against Cyber Threats. International Journal of Scientific Research (IJSR). 2025; 14(6): doi: 10.55324/josr.v4i6.2544.

[6] Chen H, Han X, Zhang Y. Endogenous Security Formal Definition, Innovation Mechanisms, and Experiment Research in Industrial Internet. Tsinghua Science and Technology. 2023; 29(2): 492–505. doi: 10.26599/TST.2023.9010034.

[7] Almaiah MA, et al. Classification of Cybersecurity Threats, Vulnerabilities and Countermeasures in Database Systems. Computers, Materials & Continua. 2024; 77(3): 6845–6869. doi: 10.32604/cmc.2024.057673.

[8] Bhurtel S. Unveiling the Landscape of Operating System Vulnerabilities. Future Internet. 2023; 15(7): 248.

[9] Alhamed M, Albahrani I, et al. A Systematic Literature Review on Penetration Testing in Networks. Applied Sciences. 2023; 13(12): 6986. doi: 10.3390/app13126986.

[10] Alhamed M, Albahrani I, et al. A Systematic Literature Review on Penetration Testing in Networks. Applied Sciences. 2023; 13(12): 6986. doi: 10.3390/app13126986.

[11] Abu Bakar R, Kijsirikul B. Enhancing Network Visibility and Security with Advanced Port Scanning Techniques. Sensors. 2023; 23(17): art. 7541. doi: 10.3390/s23177541.

[12] Park J, Yim K, Choi S, Kim G, Lee Y. Network Log-Based SSH Brute-Force Attack Detection Model. Journal of Network and Computer Applications. 2021; 186: 103063.

[13] Ruambo FA, Ruambo MM, Dandalo DT, Makwembere K. Brute-force attack mitigation on remote access services via a zero-trust-aligned software-defined perimeter. Scientific Reports. 2025; 15: art. no. 10805. doi: 10.1038/s41598-025-01080-5.

[14] Landauer M, Onder S, Skopik F, Wurzenberger M. Deep learning for anomaly detection in log data: A survey. Machine Learning with Applications. 2023; 13: 100470. doi: 10.1016/j.mlwa.2023.100470.

[15] Park J, Kim JS, Gupta BB, Park N. Network Log-Based SSH Brute-Force Attack Detection Model. Computers, Materials & Continua. 2021; 68(1): 888–901. doi: 10.32604/cmc.2021.015172.6

[16] Bangare PS, Patil KP. Enhancing MQTT security for Internet of Things: Lightweight two-way authorization and authentication with advanced security measures. Measurement: Sensors. 2024; 78: 100250. doi: 10.1016/j.measurements.2023.100250.

Published

2026-01-24

How to Cite

Hartanto, A., Margaretta Huizen, L., Firman Daru, A., & Surono, S. (2026). Penerapan Hardening Server Linux untuk Meningkatkan Keamanan Sistem Messaging IoT. Jurnal Transformatika, 23(2), 220-237. https://doi.org/10.26623/transformatika.v23i2.13776