<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JCC</journal-id><journal-title-group><journal-title>Journal of Computer and Communications</journal-title></journal-title-group><issn pub-type="epub">2327-5219</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jcc.2023.115009</article-id><article-id pub-id-type="publisher-id">JCC-125184</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Strengthening the Security of Supervised Networks by Automating Hardening Mechanisms
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Patrick</surname><given-names>Dany Bavoua Kenfack</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Alphonse</surname><given-names>Binele Abana</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Emmanuel</surname><given-names>Tonye</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Genevieve</surname><given-names>Elvira Ndjana Leka</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Department of Electrical and Telecommunications Engineering, National Advanced School of Engineering of Yaounde, University of Yaounde I, Yaounde, Cameroon</addr-line></aff><pub-date pub-type="epub"><day>10</day><month>05</month><year>2023</year></pub-date><volume>11</volume><issue>05</issue><fpage>108</fpage><lpage>136</lpage><history><date date-type="received"><day>3,</day>	<month>March</month>	<year>2023</year></date><date date-type="rev-recd"><day>26,</day>	<month>May</month>	<year>2023</year>	</date><date date-type="accepted"><day>29,</day>	<month>May</month>	<year>2023</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  In recent years, the place occupied by the various manifestations of cyber-crime in companies has been considerable. Indeed, due to the rapid evolution of telecommunications technologies, companies, regardless of their size or sector of activity, are now the target of advanced persistent threats. The Work 2035 study also revealed that cyber crimes (such as critical infrastructure hacks) and massive data breaches are major sources of concern. Thus, it is important for organizations to guarantee a minimum level of security to avoid potential attacks that can cause paralysis of systems, loss of sensitive data, exposure to blackmail, damage to reputation or even a commercial harm. To do this, among other means, hardening is used, the main objective of which is to reduce the attack surface within a company. The execution of the hardening configurations as well as the verification of these are carried out on the servers and network equipment with the aim of reducing the number of openings present by keeping only those which are necessary for proper operation. However, nowadays, in many companies, these tasks are done manually. As a result, the execution and verification of hardening configurations are very often subject to potential errors but also highly consuming human and financial resources. The problem is that it is essential for operators to maintain an optimal level of security while minimizing costs, hence the interest in automating hardening processes and verifying the hardening of servers and network equipment. It is in this logic that we propose within the framework of this work the reinforcement of the security of the information systems (IS) by the automation of the mechanisms of hardening. In our work, we have, on the one hand, set up a hardening procedure in accordance with international security standards for servers, routers and switches and, on the other hand, designed and produced a functional application which makes it possible to: 1) Realise the configuration of the hardening; 2) Verify them; 3) Correct the non conformities; 4) Write and send by mail a verification report for the configurations; 5) And finally update the procedures of hardening. Our web application thus created allows in less than fifteen (15) minutes actions that previously took at least five (5) hours of time. This allows supervised network operators to save time and money, but also to improve their security standards in line with international standards.
 
</p></abstract><kwd-group><kwd>Hardening</kwd><kwd> Supervised Network</kwd><kwd> Cyber Security</kwd><kwd> Information System</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>The digital and technological revolution is bringing its share of profound changes to the global economy. Technology is transforming jobs and skills. Companies, to satisfy their customers, are updating themselves by offering new up-to-date services in relation to technological developments. However, with this development, the world also faces an even greater cyber threat. Indeed, the information systems of organizations are very often victims of cyberattacks which affect both the company itself, whose activities are disrupted or even completely interrupted, but also impact, in a certain and sometimes irremediable way, the whole of its customers. One of the most reliable ways to prevent these attacks is to strengthen security configurations, also called system hardening or hardening.</p><p>System hardening is a collection of techniques and best practices aimed at reducing the vulnerability of applications, systems, infrastructure, firmware, and other areas. It is achieved by applying the latest patches and updates as well as following specific procedures and policies aimed at reducing the attack surface of the system [<xref ref-type="bibr" rid="scirp.125184-ref1">1</xref>] . The goal of system hardening is to reduce security risks by eliminating potential attack vectors and condensing the system attack surface. As a result, attackers and malware have fewer opportunities to penetrate a company’s IT ecosystem.</p><p>Indeed, some companies carry out the hardening of their information systems still manually, as well as the verification of the hardening is done by the execution of a script that copies the configuration files. Members of the IS security team verify that configurations comply with corporate security policies. However, these are time-consuming, error-prone tasks that require successive checks. The work thus described is very costly in terms of human and financial resources, hence the interest in automating the system hardening process as well as its verification. It is in this perspective that this work fits.</p><p>Nowadays there is a plethora of platforms allowing the automation of Hardening, like Calcom Hardening Suite, Ansibln, Puppet … etc [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] . Our work aims to remedy the weaknesses of the latter by proposing a more flexible device, capable of adapting to heterogeneous environments and having a better speed of execution as well as a lower cost of installation and maintenance.</p><p>The objectives to be achieved during this work are:</p><p>&#183; Automate the execution of the hardening of servers and network equipment of the information system.</p><p>&#183; Automate the verification of the hardening of servers and network equipment of the information system.</p><p>&#183; Generate reports of compliance of servers and network equipment of the information system aligned with the security policy of Orange Cameroon.</p><p>&#183; Correct the non-conformities noted during the verification.</p></sec><sec id="s2"><title>2. State of the Art on Hardening</title><sec id="s2_1"><title>2.1. Definition of Hardening</title><p>According to the National Institute of Standards and Technology (NIST), the official definition of system hardening is: “a process of eliminating a means of attack by patching vulnerabilities and disabling non-essential services” [<xref ref-type="bibr" rid="scirp.125184-ref1">1</xref>] .</p><p>System hardening is the process of correcting weaknesses and security vulnerabilities in systems. Hardening of systems is achieved by applying the latest patches and updates as well as following specific procedures and policies aimed at reducing the attack surface of the system [<xref ref-type="bibr" rid="scirp.125184-ref1">1</xref>] .</p><p>Hardening can also be considered the process of securing a server or computer system by reducing its attack surface or vulnerability surface and its potential attack vectors. It is a form of protection against cyberattacks that involves closing loopholes in the system that cyber attackers frequently use to exploit the system and gain access to sensitive user data.</p><p>Hardening is therefore not a curative action and must be applied in order to avoid a problem and not following a problem. Similarly, an entire standard is not to be taken and applied blindly. However, some “good ideas” can be extracted and applied. Relying on hardening guides is a good basis for defining the prerequisites that the company’s machines (client workstations and/or servers) must meet. By focusing on having these measures in place, a number of malicious acts can already be prevented. The security of the information system is all the better, as shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>.</p></sec><sec id="s2_2"><title>2.2. Importance of Hardening</title><p>Cyber security means such as VPNs, DMZs, anti-viruses, IDS/IPS are perimeter security solutions. They make it possible to implement barriers to prevent hackers from gaining access to the secure perimeter. However, they do not ensure the security of systems once there is a potential intrusion. This is where system hardening comes in. Indeed, hardening allows us to take into account hypotheses such as: the intrusion of the perimeter to be protected or the malicious actions of an employee.</p><p>If very often some companies do not take the subject of system hardening very seriously, there are several reasons why they should integrate it into their security strategy.</p></sec><sec id="s2_3"><title>2.3. Types of Hardening</title><p>Although the definition of systems hardening applies to an organization’s entire IT infrastructure, there are several subsets of this idea that require different approaches and tools [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] .</p><p>&#183; Network hardening</p><p>Network devices are hardened to prevent unauthorized access to a network’s infrastructure. In this type of hardening, vulnerabilities in the management and configuration of devices are sought and corrected in order to prevent their exploitation by malicious actors who wish to gain access to the network. Increasingly, hackers are using weaknesses in network device configuration and routing protocols to establish a persistent presence in a network rather than attacking specific endpoints.</p><p>&#183; Server hardening</p><p>The process of server hardening involves securing a server’s data, ports, components, functions, and permissions. These protocols are executed system wide on the hardware, firmware and software layers.</p><p>&#183; Application hardening</p><p>Application hardening focuses on software installed on the network. An important aspect of application hardening sometimes referred to as software hardening or software application hardening is applying patches and updating vulnerabilities. Again, patch management through automation is often a key tool in this approach.</p><p>Application hardening also involves updating or rewriting application code to increase its security, or deploying additional software security solutions.</p><p>&#183; Data base hardening</p><p>Database hardening focuses on reducing vulnerabilities in digital databases and Database Management Systems (DBMS). The objective is to strengthen the repositories of data, as well as the software used to interact with this data.</p><p>&#183; Operating system hardening</p><p>Operating system hardening is all about securing a common target of cyberattacks: a server’s operating system (OS). As with other types of software, hardening an operating system according to <xref ref-type="fig" rid="fig2">Figure 2</xref> typically involves patch management that can monitor and automatically install updates, patches, and service packs.</p></sec><sec id="s2_4"><title>2.4. How to Harden?</title><p>System hardening is a variable process. When it must be carried out, a list of hardening controls for the systems to be executed must be established upstream, taking into account the company’s security policy and referring to the system hardening standards which are published by the organizations security such as CIS Center or NIST.</p><p>Once the hardening checks have been implemented on the equipment, it is necessary to check that they have been carried out in accordance with the hardening procedure shown in <xref ref-type="fig" rid="fig3">Figure 3</xref>.</p></sec><sec id="s2_5"><title>2.5. Advantages/Disadvantages</title><p>Advantages</p><p>Hardening of systems brings us to [<xref ref-type="bibr" rid="scirp.125184-ref4">4</xref>] :</p><p>&#183; The securing of the system: By reducing the attack surface that cybercriminals can use, you will rely on a more secure system both actively and passively. This is due, among other things, to the fact that you will be able to implement more secure passwords. By reducing the attack surface that cybercriminals can use, you will rely on a more secure system both actively and passively. This is due, among other things, to the fact that you will be able to implement more secure passwords.</p><p>&#183; Performance improvement: Your computers will be able to run faster because you eliminate unnecessary overhead such as programs, services, users and ports that you don’t use.</p><p>&#183; Personalization: your computers will be configured according to your needs because hardening allows you to change the default settings by the manufacturer of each particular software.</p><p>&#183; A better control: at the time of the execution of the procedure, you simultaneously carry out a complete audit of your system, which leads you to obtain better control of it.</p><p>&#183; Confidentiality: at the time of the execution of the procedure, you simultaneously carry out a complete audit of your system, which leads you to obtain better control of it.</p><p>The hardening of the systems will also make it possible to comply with best practices and avoid configuration errors.</p></sec><sec id="s2_6"><title>2.6. Hardening Tools</title><p>1) Bastille</p><p>Bastille is an automatic hardening tool originally geared towards Red Hat and Mandrake Linux distributions. However, the bastille package provided in Debian (since Woody) has been modified to provide the same functionality for Debian GNU/Linux systems. It is a collection of PERL scripts that create a custom security configuration based on the answers provided by the administrator to a specific set of questions. It also performs an in-depth analysis of the system’s current hardening level and its various security flaws, thereby reducing the chances of system compromise [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] .</p><p>2) Microsoft SDL Threat Modelling Tool</p><p>Microsoft developed this tool with the aim of integrating threat modeling into the standard software development life cycle. The current version of the tool offers enhanced features such as better visualization and customization features, updated threat definitions, and more. Using this tool greatly reduces the effort required to identify security vulnerabilities and helps users take the necessary steps to counter them in the early stages of the SDL (software development lifecycle) [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] .</p><p>3) Ansible</p><p>Ansible is an open source IT automation tool that automates provisioning, configuration management, application deployment, orchestration, and many other manual IT processes [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] . Unlike simpler management tools, with Ansible users (system administrators, developers, architects) can use automation features to install software, automate daily tasks, provision infrastructure, improve security and compliance, apply system patches and share their automated processes with the entire company.</p><p>4) CalCom Hardening Automation Suite</p><p>CalCom Hardening Automation Suite (CHS) [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] is a hardening automation platform designed to reduce operational costs and improve infrastructure security and compliance. CHS eliminates breakdowns and reduces curing costs by automating every step of the curing process.</p><p>5) Puppet</p><p>Puppet is a tool that helps manage and automate server setup. To use Puppet, it is necessary to define the desired state of the infrastructure systems to be managed [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] . This is accomplished by writing infrastructure code in Puppet’s Domain Specific Language (DSL). Puppet code that will potentially be used with a wide range of devices and operating systems.</p><p>6) Chef Enterprise Automation Stack (EAS)</p><p>Chef Enterprise Automation Stack (EAS) is an automation platform enabling DevSecOps teams to build, deploy, manage and secure any application running on any infrastructure [<xref ref-type="bibr" rid="scirp.125184-ref5">5</xref>] :</p><p>&#183; Align teams through a common set of tools and processes.</p><p>&#183; Integrate conformance testing into each stage of the technology lifecycle.</p><p>&#183; Ensure consistency, speed and security of application delivery on any infrastructure.</p><p>It is not specific to hardening but can be used for this purpose.</p><p>7) CIS-CAT Pro</p><p>CIS-CAT Pro Assessor assesses a system’s cybersecurity posture against recommended policy settings [<xref ref-type="bibr" rid="scirp.125184-ref6">6</xref>] . The tool helps organizations save time and resources by supporting automated content with policy-setting recommendations based on globally recognized CIS benchmarks. The tool is kept in a location under the control of each member. Whether the organization uses virtual machines, in the cloud, in the network or on a local machine, CIS-CAT Pro helps ensure policy compliance. To allow for the greatest possible portability, CIS-CAT Pro is a Java application and requires a compatible JRE to run an assessment. Depending on the evaluation streams chosen by the organization, the JRE can reside on a target or a network drive.</p><p>8) Nessus</p><p>The Nessus tool is designed to scan a remote system and analyze various weak points that a malicious hacker can use to launch an attack. It is one of the most popular network scanners capable of checking vulnerabilities such as default password attacks, denial of service (DoS) attacks, etc. Versions after Nessus 3.0 also provide auditing functionality, helping to harden the system against known threats [<xref ref-type="bibr" rid="scirp.125184-ref2">2</xref>] .</p></sec><sec id="s2_7"><title>2.7. Comparaison between Existing Hardening Tools</title><p>A brief comparison of Hardening tools is shown in <xref ref-type="table" rid="table1">Table 1</xref>.</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Comparism table of existing Hardening tools</title></caption><table><tbody><thead><tr><th align="center" valign="middle" ></th><th align="center" valign="middle" >Chef</th><th align="center" valign="middle" >Puppet</th><th align="center" valign="middle" >Ansible</th><th align="center" valign="middle" >SaltStack</th></tr></thead><tr><td align="center" valign="middle" >Architecture</td><td align="center" valign="middle" >Client/Server</td><td align="center" valign="middle" >Client/Server</td><td align="center" valign="middle" >Client/Server</td><td align="center" valign="middle" >Client/Server</td></tr><tr><td align="center" valign="middle" >Ease of installation</td><td align="center" valign="middle" >Average</td><td align="center" valign="middle" >Average</td><td align="center" valign="middle" >Very easy</td><td align="center" valign="middle" >Average</td></tr><tr><td align="center" valign="middle" >Language</td><td align="center" valign="middle" >Procedural: specifying how to perform a task.</td><td align="center" valign="middle" >Declarative: specifying only what to do.</td><td align="center" valign="middle" >Procedural: specifying how to perform a task.</td><td align="center" valign="middle" >Procedural: specifying how to perform a task.</td></tr><tr><td align="center" valign="middle" >Scalability</td><td align="center" valign="middle" >Scalable</td><td align="center" valign="middle" >Scalable</td><td align="center" valign="middle" >Scalable</td><td align="center" valign="middle" >Scalable</td></tr><tr><td align="center" valign="middle" >Management</td><td align="center" valign="middle" >Difficult because you have to learn Ruby DSL.</td><td align="center" valign="middle" >Difficult because you have to learn Puppet DSL.</td><td align="center" valign="middle" >Very easy</td><td align="center" valign="middle" >Very easy</td></tr><tr><td align="center" valign="middle" >Interoperability</td><td align="center" valign="middle" >High</td><td align="center" valign="middle" >High</td><td align="center" valign="middle" >High</td><td align="center" valign="middle" >High</td></tr><tr><td align="center" valign="middle" >Availability in the cloud</td><td align="center" valign="middle" >Amazon</td><td align="center" valign="middle" >Amazon/Azure</td><td align="center" valign="middle" >None</td><td align="center" valign="middle" >None</td></tr><tr><td align="center" valign="middle" >Protocole of communicattion</td><td align="center" valign="middle" >Kife tool</td><td align="center" valign="middle" >SSL</td><td align="center" valign="middle" >SSH</td><td align="center" valign="middle" >SSH</td></tr><tr><td align="center" valign="middle" >Environnement(s)</td><td align="center" valign="middle" >Ubuntu, Linux, Windows, Solaris …etc.</td><td align="center" valign="middle" >GNU/Linux, Mac OS X et Windows.</td><td align="center" valign="middle" >GNU/Linux, Mac OS X and Windows.</td><td align="center" valign="middle" >Linux, Unix and Windows.</td></tr><tr><td align="center" valign="middle" >Strong points</td><td align="center" valign="middle" >-Integrates well with Git, which provides strong version control; -A large collection of recipes is available.</td><td align="center" valign="middle" >-Strong community support from Puppet Labs; -Well-developed reporting mechanism.</td><td align="center" valign="middle" >-There is no need to install the agent on systems that require configuration; -YAML is extremely easy to understand and learn.</td><td align="center" valign="middle" >6Extremely easy to use once set up; -A good reporting mechanism that allows easy visualization of all operations.</td></tr><tr><td align="center" valign="middle" >Weak points</td><td align="center" valign="middle" >-Considerable learning time is required if one is not comfortable with Ruby.</td><td align="center" valign="middle" >-For performing advanced tasks, a good knowledge of Ruby is required; -The main server does not have much control.</td><td align="center" valign="middle" >-Execution speed is often slower than other tools; -YAML is not as powerful as most other languages.</td><td align="center" valign="middle" >-The installation phase is a little more difficult; -A relatively new web interface that is much less developed than other tools.</td></tr></tbody></table></table-wrap></sec></sec><sec id="s3"><title>3. Materials, Tools and Methods</title><sec id="s3_1"><title>3.1. Material</title><p>The architecture of our supervised networks consists of servers with the operating system Red Hat version 7.x and Windows Server 2019, Cisco brand routers and switches, laptop computers</p></sec><sec id="s3_2"><title>3.2. Development Tool, Libraries and Programming Languages Used</title><sec id="s3_2_1"><title>3.2.1. Justification of the Choices</title><p>The type of tool that we decided to make to meet the needs is a web application developed using the Python language using the Django framework. To connect remotely to the equipment, we used the SSH protocol using the Paramiko Python library.</p><p>The choice of this library is justified by [<xref ref-type="bibr" rid="scirp.125184-ref6">6</xref>] :</p><p>&#183; Lines of code are relatively short;</p><p>&#183; The python code is of low complexity to understand;</p><p>&#183; The python code is of low complexity to understand;</p><p>&#183; The ease of Paramiko to integrate into an application.</p></sec><sec id="s3_2_2"><title>3.2.2. The Development Tools</title><p><xref ref-type="table" rid="table2">Table 2</xref> summarizes the main development tools used [<xref ref-type="bibr" rid="scirp.125184-ref7">7</xref>] :</p><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Development tools used</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Name of the tool</th><th align="center" valign="middle" >Description and functionality</th></tr></thead><tr><td align="center" valign="middle" >Pycharm</td><td align="center" valign="middle" >JetBrains’ PyCharm is a comprehensive integrated development environment that includes a highly automated toolchain to improve developer productivity. As the name suggests, the PyCharm IDE targets Python programmers.</td></tr><tr><td align="center" valign="middle" >Visual studio code</td><td align="center" valign="middle" >Visual Studio Code is a simplified code editor, which is free and developed in open source by Microsoft. It works on Windows, macOS and Linux. There is support for several programming languages, including C, C#, C++, CSS, HTML, Java, JavaScript, JSON, Markdown, PHP, Powershell, Python, TypeScript, YAML.</td></tr><tr><td align="center" valign="middle" >GNS3</td><td align="center" valign="middle" >GNS3 (Graphical Network Simulator) is an open source software that allows you to simulate complex networks while being as close as possible to the operation of real networks. This software provides an intuitive graphical user interface for designing and configuring virtual networks.</td></tr><tr><td align="center" valign="middle" >VMWare</td><td align="center" valign="middle" >VMware is a virtualization and cloud computing software provider. With VMware server virtualization, a hypervisor is installed on the physical server to allow multiple virtual machines (VMs) to run on the same physical server.</td></tr><tr><td align="center" valign="middle" >Git</td><td align="center" valign="middle" >Git is a development tool used for source code management. It is a free and open-source version control system used to efficiently manage small to very large projects.</td></tr></tbody></table></table-wrap></sec><sec id="s3_2_3"><title>3.2.3. Programming Language</title><p><xref ref-type="table" rid="table3">Table 3</xref> summarizes the main programming languages used [<xref ref-type="bibr" rid="scirp.125184-ref7">7</xref>] :</p><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> Programming languages used</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Name of the language</th><th align="center" valign="middle" >Description and functionality</th></tr></thead><tr><td align="center" valign="middle" >Python</td><td align="center" valign="middle" >Python is an interpreted, cross-paradigm, cross-platform programming language. It promotes structured, functional and object-oriented imperative programming. The latter is equipped with strong dynamic typing, automatic memory management by garbage collection and an exception management system; works on most computer platforms, from smartphones to mainframes. It is designed to maximize programmer productivity by offering high-level tools and easy-to-use syntax.</td></tr><tr><td align="center" valign="middle" >Django</td><td align="center" valign="middle" >Django is an open-source python framework dedicated to web 2.0 development. It’s “The web framework for perfectionists under pressure”. It is oriented for developers who need to produce a solid project quickly. As it is always complicated to start from scratch, Django offers a solid project base.</td></tr><tr><td align="center" valign="middle" >HTML</td><td align="center" valign="middle" >It is a language used to compose web pages. We speak of markup language and not of programming language, because the purpose of HTML is to frame the different elements present in a page (images, titles, paragraphs, etc.) with tags to allow them to be formatted secondarily. (via a style sheet) and to make sense.</td></tr><tr><td align="center" valign="middle" >CSS</td><td align="center" valign="middle" >CSS stands for Cascading Style Sheets. It is a style language whose syntax is extremely simple but its performance is remarkable. Indeed, CSS is concerned with the formatting of content embedded with HTML.</td></tr><tr><td align="center" valign="middle" >JavaScript</td><td align="center" valign="middle" >It’s a programming language that allows you to create dynamically updated content, control multimedia content, animate images, and everything else you can. The JavaScript language is mainly used to improve the ergonomics of a website and/or a user application interface.</td></tr></tbody></table></table-wrap></sec><sec id="s3_2_4"><title>3.2.4. Libraries</title><p><xref ref-type="table" rid="table4">Table 4</xref> summarizes the main libraries used [<xref ref-type="bibr" rid="scirp.125184-ref7">7</xref>] .</p></sec></sec><sec id="s3_3"><title>3.3. Method</title><sec id="s3_3_1"><title>3.3.1. Functionalities</title><p>The main features of our app are:</p><p>&#183; Harden configurations of one or more devices: the user performs a set of hardening procedures on the devices;</p><p>&#183; Verify that the hardening configurations have been executed correctly: the user executes the commands to verify the different hardening procedures;</p><p>&#183; Manage hardening controls: user add, modify or remove one or more controls;</p><p>&#183; Manage procedures: user adds procedures;</p><p>&#183; Manage procedures: user adds procedures;</p></sec><sec id="s3_3_2"><title>3.3.2. Nonfunctional Analysis</title><p>The technical constraints to which the application is subject are as follows:</p><table-wrap id="table4" ><label><xref ref-type="table" rid="table4">Table 4</xref></label><caption><title> Libraries used</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Name of the library</th><th align="center" valign="middle" >Description and functionality</th></tr></thead><tr><td align="center" valign="middle" >SQLite</td><td align="center" valign="middle" >SQLite is a library written in the C language that offers a relational database engine accessible by the SQL language. SQLite largely implements the SQL-92 standard and ACID properties. Unlike traditional database servers, such as MySQL or PostgreSQL, its particularity is not to reproduce the usual client-server scheme but to be directly integrated into programs.</td></tr><tr><td align="center" valign="middle" >Paramiko</td><td align="center" valign="middle" >Paramiko is used to program the sending of commands to network equipment via the SSH protocol. Using this library, users send commands that the network device will execute as if they had been entered into its CLI console from a keyboard directly attached to it. The result of these commands will be retrieved by the Python script which can display them on the administrator’s screen.</td></tr><tr><td align="center" valign="middle" >Ajax</td><td align="center" valign="middle" >Ajax is mainly used to bring interactivity within web pages while saving server resources. Indeed, Ajax allows to communicate with the server using Javascript code in the background while the page is displayed on the screen. Thus the content of the page can be modified without it being necessary to transit and display the entire page. Ajax is particularly used for updating forms and shopping carts on most websites.</td></tr><tr><td align="center" valign="middle" >Boostrap</td><td align="center" valign="middle" >Bootstrap is a free and open-source web development framework. It is designed to ease the process of developing responsive and mobile-focused websites by providing a collection of syntaxes for design patterns.</td></tr></tbody></table></table-wrap><p>&#183; The interfaces of our application must be ergonomic and user-friendly;</p><p>&#183; Availability: our application must be available at all times for use by entitled users, and must be easily accessible via any device;</p><p>&#183; Security: Our application contains personal and sensitive information, so it must comply with the rules relating to the security of computer systems;</p><p>&#183; Reliability: The results provided by the application must be reliable and effectively reflect the state of the database at the time of its interrogation, that is to say during the update of the data.</p></sec><sec id="s3_3_3"><title>3.3.3. Flowchart of the Methodological Steps</title><p>The approach adopted for the realization of our solution is illustrated in <xref ref-type="fig" rid="fig4">Figure 4</xref>.</p></sec><sec id="s3_3_4"><title>3.3.4. Tool Modelization</title><p>1) Use case diagram</p><p>The use case diagram in <xref ref-type="fig" rid="fig5">Figure 5</xref> of our solution looks like this.</p><p>2) Sequence diagrams</p><p>Sequence diagrams for performing and verifying curing are shown in <xref ref-type="fig" rid="fig6">Figure 6</xref> and <xref ref-type="fig" rid="fig7">Figure 7</xref>, respectively.</p></sec><sec id="s3_3_5"><title>3.3.5. Class Diagram</title><p>The class diagram of our solution is shown in <xref ref-type="fig" rid="fig8">Figure 8</xref> below.</p></sec></sec><sec id="s3_4"><title>3.4. Conception Tool</title><sec id="s3_4_1"><title>3.4.1. Challenges</title><p>The main challenges to be overcome in order to be able to design an automatic hardening management tool respecting the methodology described above are the following:</p><p>&#183; Create a hardening tool capable of hardening the configurations of several servers and network equipment at the same time and this in a reasonable time;</p><p>&#183; Create a tool that checks that the configurations have been executed on one or more network devices at the same time in a reasonable time;</p><p>&#183; Realize a tool that is able after the execution of the verification process to recover the controls that are not compliant and bring them back to the expected value;</p><p>&#183; Send a verification report in.csv format by email after the execution of the hardening verification;</p><p>&#183; Send confirmation messages by email after the execution of each routine;</p><p>&#183; Allow to take a.csv file containing the parameters of different controls and add them to the list of controls of the application.</p><p>&#183; Edit and delete controls;</p><p>&#183; Update curing procedures.</p></sec><sec id="s3_4_2"><title>3.4.2. System Architectures</title><p>1) Overall architecture of the solution</p><p>We propose to implement an architecture consisting of the following elements: an application server in which the backend, the webview and our paramiko library are hosted; an email server that hosts the API that allows us to send emails; the Active directory where all the user information of our tool and the database are stored.</p><p><xref ref-type="fig" rid="fig9">Figure 9</xref> below illustrates the overall architecture of our solution.</p><p>Functioning</p><p>&#183; The active directory communicates with the application server via keycloak to authenticate users.</p><p>&#183; The user via HTTP calls communicates with the webview of the application to be able to perform all the routines offered by the application.</p><p>&#183; The webview interacted with the backend through http calls as well.</p><p>&#183; Once the requests are sent to the backend, the latter is responsible for executing them.</p><p>o If it is a hardening or a verification, the backend is responsible for executing the various commands on the remote equipment thanks to paramiko which sends the commands that the equipment will execute.</p><p>o Whether adding, removing or modifying a control; once the query is passed to the backend, it executes it and asks the database to save the changes.</p><p>&#183; Once the requests are made, emails are sent to the users. This work is done by the Orange Cameroon Swagger Microservices API consumed by our application.</p><p>2) Logical solution architecture</p><p><xref ref-type="fig" rid="fig1">Figure 1</xref>0 below presents the software architecture of our solution. It highlights the software and protocols we used along with their versions.</p></sec></sec></sec><sec id="s4"><title>4. Results and Comments</title><sec id="s4_1"><title>4.1. Structural Architecture of the Application</title><p>Following the methodology presented above, we were able to set up an automatic hardening management tool called HardeningApp. The structural architecture of it is shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>1 below.</p><p>Our HardeningApp is structured as follows:</p><p>&#183; The authentication interface: it is the entry page of the application on which the user authenticates;</p><p>&#183; The home page: on this page the user to the application supervision data;</p><p>&#183; The hardening interface. Here the user enters into the application the parameters corresponding to the equipment to carry out the hardening;</p><p>&#183; The verification interface. In this page, the user checks that the hardening has been carried out by entering the parameters of the equipment on which he wishes to check the hardening. This has a sub-page that can be accessed once the verification process has been completed:</p><p>o The non-conformance correction interface where the user is presented with all control commands that have not been executed correctly and the user has the possibility to re-execute them.</p><p>&#183; The control interface. On this page the user accesses all the controls registered in the application. He can modify them, delete them or add other controls. This page consists of the following sub-pages:</p><p>o The detail interface: on which the user has access to all the characteristics of the selected control and can thus modify them;</p><p>o The interface for adding a control. The user can add a control by filling in the different characteristics of the control in the add form;</p><p>o The interface for adding several controls. The user adds multiple controls by importing a CSV file that includes all the characteristics of the controls to be added.</p><p>&#183; The log interface. On this page the user has an overview of all the activities carried out on the application. In the case of hardening verification, he can download the verification report.</p></sec><sec id="s4_2"><title>4.2. Tool Presentation</title><sec id="s4_2_1"><title>4.2.1. Home Page Interface</title><p>If the CUID and password are correct, the user goes to the home page. <xref ref-type="fig" rid="fig1">Figure 1</xref>2 illustrates the login page.</p><disp-formula id="scirp.125184-formula1"><graphic  xlink:href="//html.scirp.org/file/9-1732215x13.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: <inline-formula><inline-graphic xlink:href="/html.scirp.org/file/9-1732215x14.png" xlink:type="simple"/></inline-formula> This tab presents the active account on the application. It includes the CUID of the logged in person, their role and the log out button. <inline-formula><inline-graphic xlink:href="/html.scirp.org/file/9-1732215x15.png" xlink:type="simple"/></inline-formula> This section corresponds to the menu that gives us access to the other pages of the application. <inline-formula><inline-graphic xlink:href="/html.scirp.org/file/9-1732215x15.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x16.png" xlink:type="simple"/></inline-formula> On this part of the page we find the name of the application and its logo. <inline-formula><inline-graphic xlink:href="/html.scirp.org/file/9-1732215x15.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x16.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x17.png" xlink:type="simple"/></inline-formula> In this section, for each type of operation that can be performed on the application, the number of executions is entered. <inline-formula><inline-graphic xlink:href="/html.scirp.org/file/9-1732215x15.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x16.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x17.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x18.png" xlink:type="simple"/></inline-formula> In this part of the application, we find a graph which allows you to know the number of operations carried out on the application each month.</p><p><xref ref-type="fig" rid="fig1">Figure 1</xref>2. HardeninApp home interface.</p></sec><sec id="s4_2_2"><title>4.2.2. Hardening Interface</title><p>Once the user clicks on the menu hardening button from the home page, he is taken to the hardening page represented by <xref ref-type="fig" rid="fig1">Figure 1</xref>3 and <xref ref-type="fig" rid="fig1">Figure 1</xref>4.</p><p>Once the execution of the various hardening checks is complete, a confirmation email is sent to the user. <xref ref-type="fig" rid="fig1">Figure 1</xref>5 shows an example email after performing hardening on HardeningApp.</p><p>Depending on the user or the device, it may be necessary to change the ssh account. To do this, the user clicks on the edit SSH account button and is then redirected to the edit account page shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>6.</p></sec><sec id="s4_2_3"><title>4.2.3. Verification Interface</title><p>From the home page or from any other page, the user click on the verification button and he is directed to the verification page illustrated by the <xref ref-type="fig" rid="fig1">Figure 1</xref>7 and <xref ref-type="fig" rid="fig1">Figure 1</xref>8.</p><p>1) This part of the verification page is identical with the exception of the Execute button the hardening in this case is Exexcute the verification.</p><p>2) This page section consists of:</p><p>&#183; The loading bar that indicates execution percentage of the verification commands in a scalable manner;</p><disp-formula id="scirp.125184-formula2"><graphic  xlink:href="//html.scirp.org/file/9-1732215x20.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x21.png" xlink:type="simple"/></inline-formula> This part represents the form to be entered to carry out the hardening on an equipment. It consists: IP address fields: the user can enter one or more IP addresses of equipment of the same type; From the equipment type field: the user chooses between the different types of equipment (Red Hat Server, Windows Server, Router and Switch); From the procedure field: the user chooses the procedures to be carried out among the different procedures corresponding to his type of equipment; From the email field: the user enters his email address; Execute hardening button: it allows to start the hardening process on the equipment whose IP address has been entered; Clear All button to clear all previously filled in fields; <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x21.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x22.png" xlink:type="simple"/></inline-formula> This part of the hardening page features: The loading bar that shows in a scalable way the percentage of execution of the hardening commands; The total indications of orders and number of orders carried out which respectively represent the total number of orders to be executed and the number of orders which have actually been carried out; The OK button to stop the hardening process and possibly start another one.</p><p><xref ref-type="fig" rid="fig1">Figure 1</xref>4. Hardening interface 2.</p><p>&#183; The total indications of commands, the number of commands run and the number of non-conformities which respectively represent the total numebr of commands to be executed, The number of command that has been run and the number of commands that has not been executed with respect to the procedure;</p><p>&#183; The Go button at the non-conformities gives access to the page for correcting the non-conformities.</p><p>Once the execution of the verification process for the hardening is finished, A</p><p>confirmation mail is send containing a verification report. <xref ref-type="fig" rid="fig1">Figure 1</xref>9 represent an example of mail after the realization of the hardening verification on HardeningApp.</p><p>On the following <xref ref-type="fig" rid="fig2">Figure 2</xref>0 we have an example of verification report:</p><disp-formula id="scirp.125184-formula3"><graphic  xlink:href="//html.scirp.org/file/9-1732215x28.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: Shows the verification report heading which is a file in the CSV format. It is made up of: The IP address of the device on which the verification has been done; Implemented control codes; Procedures belonging to controls; Expression of some implemented controls; The status K.O or O.K with the condition that the control commands are well executed or not; Comments to be filled by ITN Security teams.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>0. Example of verification report.</p></sec><sec id="s4_2_4"><title>4.2.4. Terminal of the Server</title><p>Once the execution process of hardening and of verification are run, respectively the execution of hardening commands and verification commands begins at the same time at the server level. <xref ref-type="fig" rid="fig2">Figure 2</xref>1 and <xref ref-type="fig" rid="fig2">Figure 2</xref>2 show us the commands that run there during hardening and hardening verification, respectively.</p></sec><sec id="s4_2_5"><title>4.2.5. Correction of Non-Conformities Interface</title><p>Once the execution of the hardening verification process has been completed, the user has the possibility of executing once again the commands which during the realization of the hardening have not been executed correctly. To do this, the</p><p>user clicks on the Go to non-conformities button. The page it is redirected to is as shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>3.</p></sec><sec id="s4_2_6"><title>4.2.6. Control Interface</title><p>On this page, the user has access to all the controls registered in the application as shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>4.</p><p>To add several controls at the same time as shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>5 and <xref ref-type="fig" rid="fig2">Figure 2</xref>6, the user must click on the button and upload a CSV file containing all the parameters of the controls to be added the following figures illustrate the process of adding several controls.</p><p>Once the controls have been added, they can be found in the list of controls present in the application.</p></sec><sec id="s4_2_7"><title>4.2.7. Log Interface</title><p>Once the user clicks on the log button on the menu, he is redirected to the page shown in <xref ref-type="fig" rid="fig2">Figure 2</xref>7.</p><disp-formula id="scirp.125184-formula4"><graphic  xlink:href="//html.scirp.org/file/9-1732215x31.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x32.png" xlink:type="simple"/></inline-formula> This part represents the form to be entered to execute the commands for non-compliant controls on one or more equipment. It consists: -IP address fields: it includes the IP address(es) filled in during the verification already filled in; -From the type of equipment field: it includes the type of equipment chosen during the verification already filled in; -From the commands field: it contains all the commands of the non-compliant controls; -The Execute button: it allows you to start the process of executing commands on the equipment whose IP addresses are entered; -Clear all button to clear all previously filled in fields; <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x32.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x33.png" xlink:type="simple"/></inline-formula> Consist of: -The loading bar that shows in a scalable way the percentage of execution of the hardening commands; -The total indications of orders and number of orders carried out which respectively represent the total number of orders to be executed and the number of orders which have actually been carried out; -The OK button to stop the hardening process and possibly start another one.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>3. Non conformity correction interface.</p><disp-formula id="scirp.125184-formula5"><graphic  xlink:href="//html.scirp.org/file/9-1732215x34.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x35.png" xlink:type="simple"/></inline-formula> On this tab, the user can search controls based on code, equipment type, procedure and default setting. It is also possible to add one control or several at a time. <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x35.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x36.png" xlink:type="simple"/></inline-formula> This part is made up of the list that groups together all the controls and their parameters.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>4. HardeningApp control interface.</p><disp-formula id="scirp.125184-formula6"><graphic  xlink:href="//html.scirp.org/file/9-1732215x39.png?20230707175613804"  xlink:type="simple"/></disp-formula><p>Legend: <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x40.png" xlink:type="simple"/></inline-formula> On this tab, user can search logs based on date, IP address, procedure and user. <inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x40.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="//html.scirp.org/file/9-1732215x41.png" xlink:type="simple"/></inline-formula> This part consists of the list which includes all the logs and their parameters, namely the date of the operation, the user who carried it out, the IP address of the equipment on which it is carried out, the procedures used, the type of routine (hardening, verification and addition/removal/modification of a control), the type of equipment and possibly a verification report that the user can download.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>7. HardeningApp Log Interface.</p></sec><sec id="s4_2_8"><title>4.2.8. Checking Configuration Files</title><p>Once the hardening configurations had been executed and verified, we executed a script on the test server which returned the configuration files that we browsed.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>8 proves that the “Make sure address space randomization (ASLR) is enabled” check is applied because the kernel.randomize_va_space parameter is set to 2.</p><p><xref ref-type="fig" rid="fig2">Figure 2</xref>9 shows us that the control:</p><p>&#183; “Ensure password expiration is 90 days” is enforced because PASS_MAX_ DAYS is set to 90;</p><p>&#183; “Make sure the minimum number of days between password changes is</p><p>configured” is not correctly applied because the PASS_MIN_DAYS parameter is set to 0 instead of 1.</p><p>&#183; “Make sure the minimum length of a password is 8” is not correctly enforced because the PASS_MIN_LEN parameter is set to 5 instead of 8.</p><p>&#183; “Ensure password expiration warning days are 7” is applied because the PASS_WARN_AGE parameter is set to 7.</p><p><xref ref-type="fig" rid="fig3">Figure 3</xref>0 shows us that the “Make sure the warning message is configured” check is executed correctly because the message in the warning banner is correctly configured.</p><p><xref ref-type="fig" rid="fig3">Figure 3</xref>1 shows us that the “Make sure SELinux mode is enforced” check is executed because the SELinux is in “enforcing” mode.</p></sec></sec></sec><sec id="s5"><title>5. Conclusion</title><p>The main objective of the work that we had to carry out was to strengthen the security of information systems by automating hardening mechanisms. We started by presenting the basic notions relating to hardening, then a methodological approach was adopted for the realization of this work by using automating the mechanisms of hardening of IS by a Web application. Through this, we</p><p>were able to achieve the objectives defined at the start by making the choices of development tools, the hardening standards appropriate to our context, but also by setting up the architectures and design diagrams essential to the realization of our tool.</p><p>Thus, our application called HardeningApp was born with the following features:</p><p>&#183; Automatic hardening of servers and network equipment;</p><p>&#183; Verification of hardening configurations;</p><p>&#183; Updating hardening procedures through adding, removing and modifying controls.</p><p>It appears that the work carried out gives satisfactory results, thus allowing any administrator of information systems to save time and efficiency in the management of hardening. All these functionalities are exposed in the f.</p><p>&#183; Beyond hardening, build functionality that would provide access to server terminals and physical network equipment to perform various routines;</p><p>&#183; Improve the accuracy of audit reports.</p></sec><sec id="s6"><title>Conflicts of Interest</title><p>The authors declare no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s7"><title>Cite this paper</title><p>Kenfack, P.D.B., Abana, A.B., Tonye, E. and Leka, G.E.N. (2023) Strengthening the Security of Supervised Networks by Automating Hardening Mechanisms. Journal of Computer and Communications, 11, 108-136. https://doi.org/10.4236/jcc.2023.115009</p></sec></body><back><ref-list><title>References</title><ref id="scirp.125184-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">(2022) Durcissement des systèmes: Introduction. https://social.technet.microsoft.com/wiki/contents/articles/25992.durcissement-des-systemes-introduction-fr-fr.aspx</mixed-citation></ref><ref id="scirp.125184-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">(2022) Best Hardening Tools.https://www.calcomsoftware.com/best-hardening-tools/</mixed-citation></ref><ref id="scirp.125184-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Guide Complet du Durcissement des Systèmes en 2022 (2022).https://www.ninjaone.com/fr/blog/guide-complet-du-durcissement-des-systemes-en-2022/</mixed-citation></ref><ref id="scirp.125184-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">(2022) Durcissement ou durcissement De quoi s’agit-il, à quoi sert-il et comment l’appliquer en informatique? https://www.informatique-mania.com/linformatique/durcissement/</mixed-citation></ref><ref id="scirp.125184-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Chef Enterprise Automation Stack (2022).  https://www.chef.io/products/enterprise-automation-stack#:~:text=Chef%20Enterprise%20Automation%20Stack%20(EAS,stage%20of%20the%20technology%20lifecycle</mixed-citation></ref><ref id="scirp.125184-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">(2022) What Is the Difference between Paramiko and Netmiko?  https://fr.linuxteaching.com/article/what_is_the_difference_between_paramiko_and_netmiko</mixed-citation></ref><ref id="scirp.125184-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Leka, G.E.N. (2022) Design and Production of an Automatic Management Tool for the Hardening of Servers and Network Equipment. End-of-Study Dissertation with a View to Obtaining the Design Engineer Diploma in Telecommunications Engineering at ENSPY, UYI.</mixed-citation></ref></ref-list></back></article>