Recently, I got e-mail from Microsoft Azure Safeguards Team saying that there was a complaint of malicious activity originating from my deployment (VM).
Description is: "SSH Brute Force".
Now, I wasn't even remotely sure what this means. That someone used my VM for some malicious activity, and brute forced into it, or used it to brute force somewhere else?
I'm pretty sure no one had access to my Ubuntu Azure VM since last password change.
It was said that all this may result in suspension of my deployment. And I can't afford that because this machine is used to deploy a business application.
So my question is - what methods of protection should I look into, in order to prevent incidents as the one described above? What else should I use besides firewall on a Linux VM in cloud(Azure)? For now, the port 22 is closed, until I resolve this issue.
Thanks.