Whitelisting, Blacklisting and Your Security Strategy

Discussion in 'other security issues & news' started by Minimalist, Jan 2, 2019.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    https://www.twistlock.com/2019/01/02/whitelisting-blacklisting-security-strategy/
     
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I have always used white-listing, I first started with System Safety Monitor and then I switched to EXE Radar. It's a pretty good way to block malware from running and even if they manage to run, they can't simply abuse system related tools, because that's monitored too.
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    For me it was: Process Explorer, System Safety Monitor, Malware Defender, SRP. I liked Malware Defender the most but don't use whitelisting approach at the moment.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    So you have also stopped using SRP, that's news to me I thought you was a big fan of this approach? I haven't even used an AV since 2008, if you download apps from trusted sources you should be able to stay safe. I do use VirusTotal, but it's not bulletproof of course. And I rely heavily on behavior blockers like SpyShelter.
     
  6. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,885
    Location:
    Slovenia, EU
    Yes I switched from whitelisting to blacklisting awhile ago. At the moment I see no need to use whitelist approach and prefer to just use set-and-forget blacklist solution.
     
  7. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    That's my solution also due to its features and avaliable security profits - granular controll/rules and processes/locactions restriction are probably the most important.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I would love to use a blacklisting solution, but most if not all AV's are crap IMO. They are either too bloated and/or bad for privacy, I don't really trust them.

    Yeah, I always monitor apps for suspicious behavior. But advanced malware will probably easily bypass SpyShelter. And no matter what some "experts" say, I believe that outbound firewalls remain important, most malware will need to connect out.
     
  9. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    Haha...finally...the voice of rationality :thumb:
    According to SS...I know that's the very powerful app altough probably we could find malware able to break its protection but...at present I didn't see an examples "in the wild" or as a result of some tests.
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    Well, I still think SS should be improved, it should have the ability to automatically block process hollowing and malware trying to access browser data.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.