STRENGTHENING THE SECURITY OF WEB SERVERS
A STUDY IN HARDENING
Abstract
This scientific paper discusses the importance of hardening web servers as a key measure to strengthen the security of these systems. Hardening consists of implementing security configurations and practices that reduce vulnerabilities and increase protection against attacks. The text highlights the need to regularly update server software, as outdated versions can contain vulnerabilities that facilitate unauthorized access. In addition, it is important to configure servers correctly by disabling unnecessary services and setting appropriate permissions. The use of SSL/TLS certificates is recommended to ensure the confidentiality and integrity of the transmitted data. Authentication management and access control is also covered, emphasizing the importance of using robust authentication, strong passwords, and role-based restrictions to limit access to sensitive resources. Measures to protect against attacks, such as firewalls and the implementation of proper password policies, are mentioned. In addition, the importance of proper monitoring and logging to identify and investigate suspicious activity on servers is highlighted. Activity logs are valuable for security, but they can also be targeted by attackers, so it is important to protect them from unauthorized access. The article mentions the Nessus tool, which is a widely recognized network security tool. Nessus assists in vulnerability analysis, compliance analysis, and provides detailed reports. Tests will be conducted using Nessus to identify possible points of failure and obtain information on how to fix them. The methodological procedures involve taking proactive measures to strengthen web server security, including using Nessus to perform vulnerability testing. The goal is to identify and mitigate potential vulnerabilities that can be exploited by attackers to protect sensitive information and avoid serious consequences, such as data loss and service interruption.
Keywords: Hardening. Cybersecurity. Web Servers. Mitigation. Access.
Copyright (c) 2025 Evandro Ferreira Melo Pires, Leonardo Araújo dos Santos, João Emmanuel D’ Alkmin Neves (Autor)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Copyright Statement
- The publication reserves the right to make normative, orthographic and grammatical changes in the originals, in order to maintain the cultured standard of the language, respecting, however, the authors' style;
- Final proofs will not be sent to authors;
- The originals will not be returned to the authors;
- Authors retain full rights to their works published in the Fatecnológica journal, and their deposit or republication is subject to the indication of first publication in the journal, through the CC-By license;
- The original publication source must be recorded.
- The opinions expressed by the authors of the articles are their sole responsibility.
