Skip to Content
View all events

Linux Security from Zero to Hero

Published by O'Reilly Media, Inc.

Intermediate content levelIntermediate

What you’ll learn and how you can apply it

  • Understand the various parts involved in making Linux secure
  • Apply security to the boot process, devices, file systems, users, and more
  • Find weak spots in your system security
  • Secure storage devices using encryption
  • Run any application in an environment that is secured with SELinux or AppArmor
  • Use auditd to trace security-related issues

Course description

Linux has become the core operating system in data centers and in the cloud, offering advanced security features that are a crucial part of using Linux and making sure your projects are secure. This course with Sander van Vugt is an exploration of what Linux security is and how you can incorporate good security practices into your projects.

You’ll start by exploring how Linux security can be applied at different levels. Designed to follow a logical flow, the course then addresses how to boot securely and secure device access before moving into a discussion on how to apply user, file-based, and network security. You’ll end by examining how to use mandatory access control to completely lock down your Linux system.

This is a course where you’ll learn by doing—with each section containing hands-on demos that you can follow during the class or after.

This live event is for you because...

  • You want to make sure your Linux infrastructure is secure.
  • You want to deepen your knowledge before taking the RHCSA, the LFCS, or the Linux+ exam.
  • You want to secure your systems from an overall understanding of Linux security options.
  • You want to learn how to use SELinux to run applications in a protected way.

Prerequisites

Recommended preparation:

Recommended follow-up:

Schedule

The time frames are only estimates and may vary according to how the class is progressing.

Understanding Linux security (20 minutes)

  • Permissions and capabilities; boot and physical security; authentication and authorization security; filesystem-related security; understanding network security; understanding mandatory access control

Boot and physical security (50 minutes)

  • Securing the bootloader; using encryption to secure storage devices
  • Break

Authentication-related security (50 minutes)

  • Understanding user login; using privileged access management for secure authentication and authorization
  • Break

Filesystem-related security (40 minutes)

  • Standard permissions and special permissions; access control lists; extended attributes

Network security (30 minutes)

  • Linux firewall solution architecture; iptables and nftables; firewalld and UFW
  • Break

Logging and auditing (30 minutes)

  • Logging securely; interpreting audit logs; adding auditd rules

SELinux mandatory access control (80 minutes)

  • Understanding mandatory access control; securing default services with SELinux; using SELinux users and roles; securing any service with SELinux
  • Q&A

Your Instructor

Sander van Vugt

linkedinXlinksearch

Skills covered

  • Linux
  • Penetration Testing / Ethical Hacking
  • Network Security
  • Application Security