Advertisement
Promo

Security threats Toolkit

Security experts look to 'whitelisting' future

Munir Kotadia and Brett Winterford ZDNet Australia

Published: 28 May 2008 10:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The IT security industry has come to a frank realisation that the current approach to preventing malware is simply not working. Is whitelisting, which is the reverse of our current approach, the answer?

Whitelisting is the process by which only pre-approved applications are able to execute on a network, while unknown and unwanted ones are blocked. It is the opposite of today's approach, by which applications are free to run unless an administrator has moved to block them.

Speaking at the AusCERT 2008 security conference, Graham Ingram, general manager of AusCert (Australian Computer Emergency Response Team), said today's blacklisting approach is simply not working. Defences against malware, he said, can be completely undermined "by the click of a mouse or the enter key of a user".

Scott Charney, vice president trustworthy computing group at Microsoft, said "most people who run machines actually don't know what is executing on their machine".

"I think [whitelists] are a natural progression," said Ingram. "I think the realisation [is] that blacklisting only had a limited life and we're getting towards the end of that."

"I am not so sure that we can get to a place of feeling confident in our infrastructure without doing whitelisting," added John Stuart, chief security officer of Cisco Systems.

I think the realisation is blacklisting only had a limited life and we're getting towards the end of that

Graham Ingram, AusCert

While most at the conference agreed that whitelisting is the only available option, the model by which the industry goes about implementing it is the subject of debate.

Security vendor Lumension Security (previously called Patchlink) is hopeful that the problem can be addressed at the application layer, so future security software tools will incorporate the principles of whitelisting.

These tools, according to Andrew Clarke, senior vice president of Lumension Security, would ensure that "if someone is introducing a rogue application into an organisation and it's not on the whitelist and it's not a known good, it won't run."

But Microsoft advocates taking the whitelist concept further.

"We really do need an environment where things cannot execute without the user making certain choices," says Microsoft's Charney. "There are some fundamental engineering changes that have to happen."

Security, says Charney, needs to be built into the "trusted stack" — incorporated not just in software but in hardware.

"We have to start rooting trust in the hardware, because it is easier to manipulate software than hardware," he told ZDNet.com.au. "You'll see more and more hardware-linked functionality like BitLocker in Vista."

BitLocker is a function within enterprise versions of Windows Vista that encrypts the hard disk and only allows it to work on a specific machine. It can also be...

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters