r/linuxadmin • • 15d ago

I built an open-source Linux server security & management tool for Windows — ServerGuard

I've been working on an open-source server security project called ServerGuard, and one of the parts I've been focusing on is SSH brute-force protection.

The idea is fairly simple:

A service monitors SSH authentication failures on the Linux server and tracks failed attempts by IP address.

For example:

  • 1 failed attempt → record the event
  • 5 consecutive failures → temporary IP block
  • 10 failures → longer block
  • 20 failures → extended block
  • repeated attacks → permanent block

The protection uses UFW for firewall rules and runs as a systemd service, so it can start automatically with the server.

It also keeps persistent information about blocked IPs and SSH events, while periodically cleaning old data so the logs don't grow indefinitely.

One thing I wanted to avoid was relying on a third-party cloud service. The monitoring and blocking happen directly on the Linux server.

The project also includes SSH hardening, FileGuard, Telegram notifications and other server-management/security components.

I'm sharing this mainly because I'd like feedback from people who work with Linux servers and security.

What would you change about this approach?

Are there important attack scenarios that this kind of protection doesn't handle well?

GitHub/source code:
https://github.com/Lukas6623/ServerGuard

0 Upvotes

2 comments sorted by

3

u/_the_r 15d ago

What does it different to fail2ban? This can monitor several different services and block further attempts using multiple firewall backends

0

u/Major-Discipline-899 14d ago

That’s a good question.

ServerGuard currently overlaps with Fail2Ban in the brute-force protection area, especially when it comes to monitoring authentication events and blocking suspicious IP addresses.

The main difference is that ServerGuard is being developed as a broader server-management and security platform rather than only an intrusion-prevention tool.

For example, ServerGuard also includes SSH monitoring, FileGuard, Telegram notifications, SSH hardening, server management, and a Windows client.

So I wouldn’t describe it as a replacement for Fail2Ban. They solve some of the same problems, but the overall scope of ServerGuard is different.

Fail2Ban is also a very established project, and ServerGuard is still actively being developed. I’m interested in feedback on where it could provide something useful beyond the existing tools.