Coming: A Change in Tactics in Malware Battle
To keep up with the criminals, antivirus companies plan a major shift in approach, called 'whitelisting'.
Erik Larkin

The technique, known as whitelisting, could help protect your computer. But though some security apps already use this approach (see the next page for our look at a few free downloads), it can also make using your PC a huge annoyance.
"Whitelisting is probably at the top of the list for what the industry needs to move towards," says Jeff Aliber, senior director of product marketing with antivirus maker Kaspersky Labs.
For Kaspersky and other antivirus companies, the ocean of malicious software in circulation today may mean that just tracking known good software will be easier than trying to keep tabs on all the bad stuff. For example, Symantec, which has been pushing for an industry shift to whitelists since last year, anonymously tracks new applications that appear on PCs participating in its Norton Community Watch program. During one week last November, more than half of the 54,000 new executables reported by Community Watch were malicious, says Carey Nachenberg, a vice president and developer with Symantec Research Labs.
In the face of that sobering reality, Kaspersky this summer will release its first consumer antivirus products that bring in whitelists. It will use lists from Bit9, a whitelisting company that maintains a 6.3 billion-strong list of known good applications. The new Kaspersky applications won't automatically block programs not on the Bit9 list, but instead will focus scanning resources on those programs that Bit9 doesn't recognize. Theoretically, that could allow for more careful scrutiny of unknown files with less risk of false alerts.
But that huge number in Bit9's list--6.3 billion--highlights the risk of using whitelists to fully block unknown apps. Nobody has a full list of all good software, so you can't block everything not on a list without eventually blocking some great but relatively unknown programs. And displaying a pop-up that asks you to decide whether an unknown app is okay to run ensures that you'll eventually make the wrong call and break your software or even your system. Most antivirus companies rightly make every effort to minimize the number of alerts that ask us to make a decision; an overreliance on whitelists could roll back those improvements.
- Page 1 of 3
- Next ยป
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Laptop Showcase
A Guide to Business IT
Tags at a Glance
Related Antivirus and Security Articles
- New Utility Offers IWeb Search Engine Optimization RAGE Software on Tuesday announced the release of iWeb SEO Tool 1.0, a new utility for iWeb users. It's free to download and...
- What's Keeping Me? 1.3 One of the most frustrating issues many OS X users experience is trying to unmount a disk image, hard drive, or network...
- VirusBarrier Update Improves Performance Utility software-maker Intego on Tuesday released an update for its Mac antivirus application, VirusBarrier.
- Don't Buy Antivirus Software, Vendor Says Threats today go far beyond viruses, so a standalone solution won't make it, Trend Micro manager says.
- MercuryMover 2.0 A couple years ago--it's difficult to believe it's been that long--I covered MondoMouse, a great utility that lets you move or...
Best Prices on System Utilities
VMware Fusion (Full Product, Mac)Price: $41.99
Windows Live OneCare 2.0 (Full Product)Price: $23.78
Norton Partition Magic 8.0 Rev1RetailPrice: $17.99
Parallels Desktop (Full Product)Price: $20.00
Windows Live OneCarePrice: $19.95
Norton SystemWorks 11.0 (Full Product)Price: $29.95
- CDW Security Center Is your data protected? Visit the CDW Security Center Learn where you may be vulnerable and how to address those risks.
- Asus Laptop Showcase Ultra-fashionable thin and light notebooks with SmartLogon Face Recognition. Find out more...
- HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...








"Coming: A Change in Tactics in Malware Battle" Comments