You don't need to do anything, simple as that:
As you can see, Ubuntu is patched one-hundred percent, 100% of the time.
http://secunia.com/advisories/product/32688/?task=advisories
Windows (I'll only compare Ubuntu to Windows 7, because it is the most secure Windows OS)
Well, it is un-patched 100% of the time, currently it is rated as "Highly critical"
http://secunia.com/advisories/product/27467/?task=advisories
Edit:
You should not mess with the Firewall because Ubuntu already comes shipped with no open ports.
Ubuntu Linux is supplied with powerful firewall technology known as iptables built-in, & if you mess with the default settings, you could actually make it less secure by accidentally opening ports etc.
However, if you still want to mess with your firewall, then you can install the front end program UFW or Firestarter, you can find these programs in Ubuntu Software Center
http://www.youtube.com/watch?v=G5ZpspkfbDg