• On GameSpot: So-called 'Halo killer' gets 23 to life
July 18, 2008 2:47 PM PDT

Security Bites 108: Understanding white listing

by Robert Vamosi
  • Font size
  • Print
  • 2 comments

To put it simply, the concept of "white listing" is to define a set of software, a set of vendors, and allow only those trusted applications or files from those vendors to run on your machine. If a file or application is not approved, it will not run. This is the opposite of how we've blocked malware from our machines in the past.

In 2007, Symantec detected more than 1 million viruses, with two-thirds created within the calendar year. Loading 1 million antivirus signatures or even a percentage of that if generic signatures are used is a pretty serious undertaking. The idea here is that maybe we should only be loading signatures for the good files.

So far, the idea is only being implemented in the enterprise space. Still, it's a interesting idea. On the desktop it's already being used to stop spam, so why not use white lists to block malware as well?

Massachusetts-based Bit9 has created one of the largest catalogs of "known good" and "known bad" applications. Its Global Software Registry (GSR) serves as the policy enforcement center for Bit9's enterprise offerings. Recently, desktop antivirus vendor Kaspersky announced a partnership with Bit9 that will allow it to use the GSR in its upcoming desktop products in 2009.

This week on the Security Bites podcast, CNET's Robert Vamosi talks with Tom Murphy, chief strategy officer for Bit9, about white listing and its potential for the future.


Listen now: Download today's podcast

As CNET's resident security expert, Robert Vamosi has been interviewed on the BBC, CNN, MSNBC, and other outlets to share his knowledge about the latest online threats and to offer advice on personal and corporate security. Listen to his podcast at securitybites.cnet.com or e-mail Robert with your questions and comments.
Recent posts from Security Bites podcast
Security Bites 122: IBM sees security challenges ahead
Security Bites 121: What Microsoft's Geneva means for online IDs
Security Bites 120: When social networks host malware
Security Bites 119: Does the Internet need its own Interpol?
Security Bites 118: Voting in America
Security Bites 117: How 'Clickjacking' attacks hide behind the mouse
Security Bites 116: Investigating data breaches
Security Bites 115: Inside ID fraud's underground forums
Add a Comment (Log in or register)
by July 18, 2008 3:59 PM PDT
It's an interesting idea until someone manages to get a virus to masquerade as a white listed item then it's a really dumb idea.
Reply to this comment
by sti774 July 18, 2008 6:11 PM PDT
that's why you use hashing algorithms to prevent that!
Reply to this comment
Subscribe to the Security Bites podcast

Subscribe to this podcast using an RSS reader other than iTunes

Subscribe to this podcast using iTunes

advertisement

Inside the Apple, er, Microsoft Store

Although Redmond's foray into retail bears a big resemblance to Apple's approach, Microsoft has added some distinctive features to draw casual PC buyers and techies alike.

Big marketing budget drives Moto Droid sales

Verizon and Motorola are spending big bucks--$100 million--on marketing the new smartphone, and it looks like it will pay off with 1 million devices sold by year's end.

About Security Bites podcast

Backdoors, pharming, botnets, phishing, rootkits, viruses, worms. Feeling vulnerable? Every Friday, CNET.com's Robert Vamosi will tell you about the latest security threats, what's coming, and how to protect your system.



View all Security Bites podcast episode blog entries

Add this feed to your online news reader

Security Bites podcast topics

Meet the host of Security Bites
Robert Vamosi Robert Vamosi has appeared on CNN, NBC, ABC, MSNBC, and various other media outlets as an expert on computer viruses, spyware, identity theft, phishing, and other criminal activities on the Internet.
advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right