Evaluating the Effectiveness of Center of Internet Security Benchmark for Hardening Linux Servers Against Cyber Attacks
Downloads
The security of operating systems is critical in safeguarding digital infrastructure, particularly server environments vulnerable to cyberattacks. One proven approach to enhancing OS security is hardening, which involves minimizing the system's attack surface. This study evaluates the effectiveness of the Center for Internet Security (CIS) Benchmark in hardening Ubuntu Server 22.04 against cyber threats. Using the PPDIOO framework, the research implemented hardening procedures via Ansible automation and conducted experimental tests comparing a hardened server against a standard (non-hardened) counterpart. Both servers were subjected to simulated attacks including DDoS, Port Scanning, Brute Force, Web Scanning, and Web Crawling. The results demonstrate a marked improvement in resistance for the hardened server, with attack success rates significantly reduced: 11% for DDoS (versus 94% on the standard server), 0% for Port Scanning, Brute Force, and Web Crawling (versus 20–100% on the standard server), and 67% for Web Scanning (versus 100% on the standard server). These findings underscore the substantial protective advantage conferred by the CIS Benchmark. The study contributes to the field by offering empirical evidence of CIS Benchmark's applicability to modern Linux environments and highlights the value of integrating automated hardening and attack simulations in cybersecurity practices. Future work should examine scalability across different OS platforms and real-world enterprise deployments.
Copyright (c) 2025 Bambang Irawan, Kholid Nur Sheha, Mosiur Rahaman, Nixon Erzed, Agus Herwanto

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.



