Moonlight Digital Logo Moonlight Digital
← กลับหน้าหลัก ← Back to Home

5 ขั้นตอนเพิ่มความปลอดภัยให้ Cloud Server ป้องกันแฮกเกอร์ 5 Cloud Server Security Best Practices to Prevent Hackers

คู่มือแนะนำวิศวกรรมความปลอดภัยเบื้องต้นบน Linux Server ตั้งแต่การตั้งค่าพอร์ต SSH คีย์ไฟร์วอลล์ และระบบป้องกัน Fail2ban เพื่อความปลอดภัยขั้นสูงสุดของข้อมูลบริษัท An in-depth security engineering guide to secure Linux servers, configuring custom ports, key authentications, UFW rules, and fail2ban jails.

5 ขั้นตอนเพิ่มความปลอดภัยให้ Cloud Server ป้องกันแฮกเกอร์

เมื่อเราทำการติดตั้งคลาวด์เซิร์ฟเวอร์เสร็จสิ้น ไม่ว่าจะเป็นบนค่าย AWS, Google Cloud หรือ DigitalOcean ระบบปฏิบัติการที่เพิ่งรันขึ้นมาใหม่มักจะมาพร้อมกับการตั้งค่าพอร์ตและสิทธิ์เข้าถึงที่เป็นค่าเริ่มต้น (Default Configurations) ซึ่งเปรียบเสมือนบ้านใหม่ที่ยังไม่ได้ล็อกหน้าต่าง แฮกเกอร์และสแกนบอทบนเครือข่ายอินเทอร์เน็ตจะทำการสแกนกวาดหาไอพีเปิดตลอด 24 ชั่วโมงเพื่อพยายามเดารหัสผ่านและหาช่องโหว่ในการยึดครองเซิร์ฟเวอร์เพื่อนำไปทำเป็นฐานยิงสแปม หรือฝังมัลแวร์เรียกค่าไถ่ (Ransomware)

บทความนี้เป็นคู่มือเชิงปฏิบัติตามมาตรฐานสากลเพื่อเพิ่มความมั่นใจในการดูแลระบบและความปลอดภัยให้คลาวด์เซิร์ฟเวอร์ของธุรกิจคุณ ด้วย 5 ขั้นตอนสำคัญดังนี้ครับ:


1. เปลี่ยนพอร์ตควบคุม SSH หลัก (Change Default SSH Port)

โดยเริ่มต้นพอร์ตสำหรับเข้าควบคุมเซิร์ฟเวอร์ระยะไกลผ่านโปรโตคอล SSH จะใช้ Port 22 เสมอ ทำให้ตกเป็นเป้าหมายแรกในการสุ่มรหัสผ่านเดาโจมตี (Brute-Force Attacks)

วิธีการเปลี่ยนพอร์ต SSH:

1. ล็อกอินเข้าเซิร์ฟเวอร์หลักแล้วเปิดไฟล์คอนฟิก:

sudo nano /etc/ssh/sshd_config

2. มองหาบรรทัด #Port 22 หรือ Port 22 แล้วเปลี่ยนตัวเลขเป็นพอร์ตช่วงส่วนตัว (เช่น Port 2222 หรือ Port 9122)

3. บันทึกไฟล์แล้วทำการสั่งรีสตาร์ทบริการ SSH:

sudo systemctl restart sshd

(ข้อควรระวัง: อย่าลืมเปิดพอร์ตใหม่นี้บนระบบไฟร์วอลล์คลาวด์หลักของคุณก่อนตัดการเชื่อมต่อเดิม เพื่อป้องกันเซิร์ฟเวอร์ล็อกระบบไม่ให้เข้าเชื่อมต่อย้อนหลัง)


2. บังคับใช้งาน SSH Key Authentication (Disable Password Login)

การเข้าล็อกอินเซิร์ฟเวอร์ด้วยชื่อผู้ใช้งานและพิมพ์รหัสผ่าน มีความเสี่ยงที่จะโดนเดารหัสผ่านจนสำเร็จได้ หากคุณตั้งรหัสผ่านไม่ยาวเพียงพอ ทางออกที่ปลอดภัย 100% คือการ ปิดระบบพิมพ์รหัสผ่านล็อกอิน และบังคับให้เข้าเชื่อมต่อผ่านไฟล์กุญแจเข้ารหัส (SSH Key Pair) เท่านั้น

วิธีการปิดรหัสผ่านในไฟล์คอนฟิก SSH:

ค้นหาคีย์เวิร์ดเหล่านี้ในไฟล์ /etc/ssh/sshd_config และแก้ไขค่าเป็น no:

PasswordAuthentication no
ChallengeResponseAuthentication no
PubkeyAuthentication yes

จากนั้นสั่งรีเซ็ตระบบ SSH ข้อมูลไฟล์กุญแจ SSH Key จะถูกนำมาใช้แทนรหัสผ่านในการจับคู่ความถูกต้องเพื่อเปิดระบบ ทำให้แฮกเกอร์ไม่มีทางเข้าสู่เซิร์ฟเวอร์ได้เลยต่อให้รู้ชื่อผู้ใช้


3. ควบคุมและกรองสิทธิ์พอร์ตเข้าออกด้วยไฟร์วอลล์ (UFW configuration)

ระบบเซิร์ฟเวอร์ที่ดีต้องอนุญาตให้เครือข่ายภายนอกวิ่งเข้ามาคุยได้เฉพาะพอร์ตบริการของเว็บไซต์เท่านั้น ส่วนพอร์ตระบบฐานข้อมูลหรือหลังบ้านควรถูกซ่อนปิดการเข้าถึงจากสาธารณะ

คำสั่งสเต็ปการตั้งค่าไฟร์วอลล์ UFW บนระบบ Ubuntu:

# 1. อนุญาตให้เว็บเซอร์วิสทำงานปกติ
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# 2. อนุญาตให้เฉพาะพอร์ต SSH ใหม่ที่เราตั้งค่าไว้ทำงาน
sudo ufw allow 2222/tcp

# 3. สั่งเปิดระบบไฟร์วอลล์
sudo ufw enable

การตั้งค่า UFW จะช่วยบล็อกทุกสัญญะเชื่อมต่อที่แปลกปลอมเข้ามาทางพอร์ตอื่นๆ โดยไม่ได้รับอนุญาตล่วงหน้า


4. ติดตั้งระบบป้องกันบอท Fail2ban

Fail2ban คือซอฟต์แวร์อัจฉริยะที่จะคอยมอนิเตอร์ความพยายามล็อกอินเข้าระบบจากไอพีภายนอก หากตรวจพบว่าหมายเลขไอพีใดพยายามเชื่อมต่อและใส่รหัสผ่าน/กุญแจผิดติดต่อกันเกิน 5 ครั้ง (ตามที่เราตั้งไว้) ตัว Fail2ban จะไปสั่งระบบไฟร์วอลล์ให้ บล็อกไอพีนั้นถาวรทันที

ตัวอย่างไฟล์ตั้งค่าคอนฟิก /etc/fail2ban/jail.local เพื่อเพิ่มเกราะป้องกันพอร์ต SSH:

[sshd]
enabled = true
port    = 2222
filter  = sshd
logpath = /var/log/auth.log
maxretry = 5
bantime  = 86400

(ไอพีที่สุ่มเดารหัสผิด 5 ครั้งจะโดนสั่งแบนห้ามเข้าเว็บไซต์เป็นเวลา 24 ชั่วโมงเต็ม)


5. อัปเกรดความปลอดภัยของแพตช์ระบบปฏิบัติการสม่ำเสมอ

บ่อยครั้งที่ระบบล่มเนื่องจากช่องโหว่ความปลอดภัยระดับลึกของระบบปฏิบัติการ (OS Kernel Vulnerabilities) การติดตั้งสคริปต์อัปเดตแพตช์ความปลอดภัยล่าสุดเป็นประจำจะช่วยอุดรอยรั่วเหล่านั้นได้ทันเวลาก่อนจะโดนโจมตี

แนะให้เข้ามาสั่งรันคำสั่งด้านล่างนี้สัปดาห์ละ 1 ครั้ง หรือตั้งค่าระบบอัปเดตอัติโนมัติ (Unattended Upgrades) เพื่อความปลอดภัยระยะยาว:

sudo apt update && sudo apt upgrade -y

บทสรุป

การสร้างเกราะป้องกันคลาวด์เซิร์ฟเวอร์ตามขั้นตอนเชิงปฏิบัติด้านบน คือรากฐานสำคัญในการรักษาความลับและความปลอดภัยของฐานข้อมูลธุรกิจ SME เพื่อช่วยให้คุณรันเว็บไซต์และโปรแกรมอัตโนมัติได้อย่างปลอดภัยและมั่นใจสูงสุดครับ

5 Cloud Server Security Best Practices to Prevent Hackers

When you deploy a new cloud server on platforms like AWS, Google Cloud, or DigitalOcean, the default operating system configurations are active. This is similar to a new house with unlocked windows. Automated scanner bots scour the web 24/7, testing open IP ports to execute brute-force attacks, steal database assets, or install ransomware payloads.

This guide outlines the industry-standard security steps to harden your cloud Linux servers and prevent unauthorized access.


1. Modify the Default SSH Management Port

By default, remote command line access utilizes Port 22. Because this is standard, it is the first target of automated botnet scans.

How to Change Your SSH Port:

1. Log in to your server and open the SSH configuration file:

sudo nano /etc/ssh/sshd_config

2. Locate the line #Port 22 or Port 22 and update the port number to a private range (e.g., Port 2222 or Port 9122).

3. Save the changes and restart the SSH daemon:

sudo systemctl restart sshd

(Warning: Open your new custom port in your cloud provider's network firewall console before closing your active terminal connection to avoid locking yourself out of the instance).


2. Enforce Cryptographic SSH Key Authentication (Disable Passwords)

Logging in to a remote server using a username and a dynamic password is vulnerable to password guessing. A secure alternative is disabling password logins and requiring encrypted SSH Key Pairs instead.

Disabling Passwords in Your SSH Config File:

Locate these lines in /etc/ssh/sshd_config and change their arguments to no:

PasswordAuthentication no
ChallengeResponseAuthentication no
PubkeyAuthentication yes

Restart SSH. The server will now reject password entry requests and authenticate connections using SSH Keys, preventing automated password guessing.


3. Restrict Network Access Using a System Firewall (UFW)

A secure server configuration only allows public traffic on essential ports. Keep database ports and internal backend services hidden from public network scans.

Setting Up UFW Firewall Rules on Ubuntu:

# 1. Allow public web traffic
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

# 2. Allow your custom SSH port
sudo ufw allow 2222/tcp

# 3. Enable the firewall rules
sudo ufw enable

Enabling UFW drops all unsolicited packets trying to access unexposed ports.


4. Deploy Fail2ban to Auto-Block Intruders

Fail2ban is an intrusion prevention application that monitors log files for malicious signs (such as multiple authentication failures). If an external IP fails to log in 5 times in a row, Fail2ban dynamically instructs the firewall to block the IP.

Here is a working configuration file block (/etc/fail2ban/jail.local) for SSH protection:

[sshd]
enabled = true
port    = 2222
filter  = sshd
logpath = /var/log/auth.log
maxretry = 5
bantime  = 86400

(Any IP that fails login 5 times is blocked from making server requests for 24 hours).


5. Automate OS Security Patches

Zero-day exploits inside Linux system kernels can lead to data breaches. Regularly upgrading OS packages patches security flaws.

Run these update instructions weekly, or enable automated background security updates (Unattended Upgrades) to secure your system:

sudo apt update && sudo apt upgrade -y

Conclusion

Hardening your cloud server using these 5 steps protects your SME's databases and ensures your apps run on a secure infrastructure.