- 5comments
- 338comments
- 4comments
- 93comments
- 114comments
- 201comments
- 46comments
- 36comments
- 365comments
- 563comments
- 145comments
- 26comments
- 11comments
- 359comments
- 398comments
- 129comments
- 14comments
- 4comments
- 52comments
- 37comments
- 22comments
- 624comments
- 22comments
- 127comments
- 17comments
- 12comments
- 21comments
- 39comments
- 11comments
- 50comments
Chalk another one up for "Antiviruses causing more problems than solving them".
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
I would say white listing will have to happen for everything in the near future: applications, ports, URLs (including fragments!), filesystem hierarchies, basically everything.
I'm not sure it's doable with current OS architectures, though.
Isn't the model of AppArmor or SELinux a good approach to tackle this problem?