Practical tools for locking down your Linux portable

Tight Ship

Article from Issue 284/2024
Author(s):

Linux is quite secure compared to the alternatives, but you'll need a few additional steps if you really want to lock it down. We'll introduce you to some practical tools for antivirus protection, firewall configuration, and sandboxing.

It occurred to me recently that the laptop I devote to my personal use did not have the same add-on protections I routinely expect from systems I use at work. In one sense, this is understandable. (No one gets paid for integrating my personal laptop into a comprehensive security infrastructure, and no one will get fired if I get hacked.) However, the threats posed by Internet activity are very real, especially for a laptop computer that operates in public spaces behind low-tech coffee house firewalls that someone else configured. When I read about the Infostealer malware targeting Linux [1], I decided it was a good time to explore the options for using security sandboxing techniques to isolate applications. And while I was at it, I took a closer look at antivirus options and local firewall tools that would make me less dependent on the security of whatever subnet I happen to have landed in.

Of course, users expect convenience and simplicity for their home systems. Tools that are too elaborate or complicated are often ignored – or set up once and then forgotten. For my system, I set out to find convenient yet powerful tools that could provide virus protection, firewalling, and sandboxing support. Eventually I settled on the following cocktail:

  • ClamAV for virus protection
  • UFW for firewall configuration
  • Firejail for sandboxing

[...]

Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • strace and Firejail

    Software from unknown sources always poses some risks. With the strace analysis tool and the Firejail sandbox, you can monitor and isolate unknown applications to safeguard your system.

  • Security Lessons: ClamAV

    Protecting Windows clients from the big bad Internet.

  • Charly's Column

    Too many cooks spoil the broth, they say, but it could just as easily be an ingredient that isn’t part of the recipe. If you can’t reduce the number of cooks, you have to take other steps to make your broth more edible.

  • KlamAV

    Linux may not be as virus-ready as Windows, but who wants to harbor pointless malware? Now you can hunt for viruses with KDE's KlamAV, a desktop front-end for the ClamAV Open Source virus protection system.

  • Improved virus detection with ClamAV 0.94

    The latest version of the open source anti-virus scanner, ClamAV 0.94, promises to improve virus detection rates with enhanced scanning capabilities.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News