Host-based security covers the tools and practices used to protect laptops, desktops, and other end-user devices at the individual machine level. Key areas include software firewalls, OS hardening, malware protection, disk encryption, patch management, and continuous monitoring.
Host-Based Security
Your network consists of a lot of different networking equipment and a lot of hosts that are utilizing that network equipment. Let's talk about some of the things that you can do on the host, that's the laptops, desktops and the end user devices, and what you would want to do to those machines to make sure that they're secure.
When it comes to host-based security, there's a lot of things that we could implement to secure our host.
When it comes to the peripheral of your network, there's several things that we said you want to implement to secure your network. That would be things like a firewall, or an intrusion detection system or intrusion prevention system, that protects your network. Well, there are host-based systems as well. That is, just as on your network, you want to have those systems involved. You can install software, or sometimes operating systems come with it, where it's protecting the system.
An example of this is a host-based or software firewall. A software firewall could be something that you install on your host, or it could be already integrated, like Microsoft Windows has a firewall. So it could be on your host already, protecting the host already, but making sure that you're maintaining that, that it's up to date, and that you have it enabled, is going to be important. And then, same thing, host-based intrusion detection systems or prevention systems are out there as well.
And then also, disabling ports and protocols. When we're communicating across networks we actually use ports and protocols for that communication, and we can turn off certain ports and protocols so that way we're not using them. So it's recommended that you do that on your end host.
We also want to harden the operating system. The operating system is that base level of instructions, like Microsoft Windows or Linux, that's running on your machines. It comes with a lot of services enabled, once again to give you some functionality so that way it works straight out of the box and gives you certain features right away, but you're not necessarily going to use all those features. So it's recommended to:
We're going to want to make sure your machines and your hosts are protected against malware, that you have some sort of antivirus or antimalware installed and updated on your machines. Now, there are some systems out there that come with this pre-installed, like Microsoft Windows has their version that is pre-installed on the machines that's scanning for this stuff, but we're going to want to make sure that's updated.
We should probably also consider something like an endpoint detection and response. This takes things a step further. An antivirus or antimalware scans files and code and different software to see if something's wrong with that software. An endpoint detection and response actually is looking for behavior, and so it's taking that next step and seeing, is there some odd behavior that's happening on your machine that should be flagged or dealt with.
We're also going to want to protect any privileged accounts. These machines have administrator accounts, something that's going to actually be able to install software and do things at an escalated level. So it's best in practice not to give privileged accounts to end users. In fact, even my IT people who have worked for me, I make them have two different accounts: the account that they use for their regular day-to-day, them being an employee, and their account for administrative privilege, or escalated privileged accounts, so that way they can perform administrative duties on these different computers. And they use them for two different purposes.
You'll also want to practice safe browsing practices. This is where a lot of malware and things get installed on our computers, is by going to sites and places that we shouldn't be actually going to. And so this is especially important on things like servers, and servers will come with actually some safe browsing settings turned on so that way you can't make it to these sites. But make sure you're careful on where you go, do some sort of content screening and blocking, make sure that the servers are protected, because out of everything, that's going to be one of the more critical things that you're protecting on your network, is your servers.
One thing we may want to consider is disk cloning or disk imaging. That's where we take a copy of the machine and now we have a duplicate. We can use this to set up other machines once it's hardened, and then we can roll out machines faster to make sure that we're rolling out hardened machines. But another thing that this has as an added advantage: if something happens on this machine, like maybe it's corrupted, it has some malware that gets installed, we can take this disk image that's known to be good and then re-image this machine, and so then we wipe that all out. And making this fast and easy allows us to be able to overcome any kind of discrepancies or anything that happens to our machines very quickly.
We also have something called Deep Freeze. Deep freeze is like disk cloning, except it happens on the individual machine. So the individual machine creates a clone of itself, and then what happens is that somebody can get on and do whatever they want to this machine right here, but as soon as they log off, then this deep freeze returns it back to the original. What this allows is, both from a security perspective, but it also allows that user to really download and do anything they want, to be efficient and productive with what they're doing, but then when they walk away from the machine it's completely cleaned every time. And so that's what a deep freeze is.
Another thing that's becoming very standard is encrypting your hard drives. If this machine, especially on your mobile devices, ever gets stolen, you want to make sure that that information is secure. So you want to encrypt the drives on that machine. BitLocker is Microsoft's version that does that.
One thing you hear often is make sure your software is updated and patched. But how do you do that? It's not enough just to let your end users make sure that they are updating and patching their machines; a lot of times it won't happen. So you need to implement some sort of patch management. That patch management includes some sort of testing, making sure that the patches are going to be successful and not going to cause more problems than they're worth, that you deploy this consistently, that you're able to track what's happening, and be able to document the results. So patch management is a huge part of making sure that your systems are hardened and continually maintained on an ongoing basis.
And you don't want to leave out the applications that are on that machine as well, because not only does the machine's OS need to be patched and updated, but you've got software on there that needs to be updated and patched as well. So remove extra software, disable unneeded services, roles or features, and install the latest patches on those applications.
Your computer has a bunch of policies on it, policies that help manage security around it. And the thing is, if you want to implement good security organization-wide, and you want to make sure it's implemented consistently, then you're going to need some sort of mechanism to do that. Group policies do that. You can roll out group policies for your machines and it applies to all your machines.
So some of those things that you may want to consider rolling out are things like logout timers or idle timeout and screen locks, or enabling certain passwords. Making sure that things are enabled and working on the machine in a secure manner, you need to do that companywide, and group policy allows you to do that.
A lot of times mobile devices get overlooked with that, though. How do we manage, how do we roll out things from a mobile standpoint, because not the same things apply on mobile devices, things like tablets and phones. So that's where a mobile device management can come into play. You can select and purchase an MDM solution that helps you roll out mobile devices and make sure that security and things are consistently applied across your mobile devices.
And of course, everything we roll out, it's not good enough just to roll it out; we need some sort of monitoring and making sure that it's happening. Everything from the patching, like we talked about, or antivirus, or if you have an endpoint detection and response system, maybe having some sort of managed endpoint detection and response system, and logs and alerts. So things that are going to be able to monitor all this and manage all of it is going to be important.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →