Get the App
SLTechnology News&Howtos  ›  Network Security  › 

A small plan for emergency response of linux

Shulou Source: shulou.com Published: 2022-06-01 03:20:09 10月01日 Update

Earlier, another customer said that his linux machine has the characteristics of a large number of active links and high CPU. Customer preliminary disposal: disconnected, offline, restart. I suggested a step to deal with them, and as a result, there was no more information.

The recommendations are as follows:

(0) View the history command and recently open the file.

(1) confirm the daily application of the server, application process name, file path, process open port.

(2) View active processes, process open files, memory string information, privileged users.

(3) View the network link, establish the link network situation, and monitor the network situation.

(4) check the user login situation, recent login log, login user name, login IP.

(5) check boot startup, the virus will often start itself in order to start the resident system multiple times.

(6) Planning task, a kind of self-starting technique, is more common in mining viruses.

(7) key directory troubleshooting, system tmp directory, var and other virus resident path under suspicious files troubleshooting.

(8) Open ports, check open ports to see if there are any abnormal ports, which are often used for virus communication.

(9) queries such as security log, system log and application log to find anomalies from log files.

(10) Export all files and use antivirus software to scan and kill them.

(11) use MD5 value comparison, compare the file export calculation hash with the normal system file hash, and check out the problematic files.

(12) Review applications and patches to see if vulnerabilities have caused server problems, and look for other possible traces.

(13) Audit account information, existing account situation, privileged account.

(14) rootkit check, some malicious code is not easy to be detected by hidden means such as process, so use rootkit check tool.

(14) detailed analysis of the abnormal samples after obtaining them.

Tags: File situation log process virus port system application check login account user network link open information client server sample privilege Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno macOS Docker MySQL Shulou Tech Info Redmi