malware-list-bounces@dmesg.printk.net wrote on 2008-08-18 01:11:24:The problem with white-lists is who gets to decide what's on them: a) The end-user: Easy to get around - a social engineering attack. The problem is if you make all the good applications the user downloads appear identical to any random malware they download, the end-users will treat them the same. b) The network administrator: Often doesn't exist (e.g. home users), but even when they do exist, they are often too over-worked to handle a white-listing solution. For example Windows provides white-listing in policies (AFAIK), but still there is a market for AV software. The admin probably ends up authorizing anything the end-users want. (Thus leading to the same problems as a)...) c) The White-listing software company: Now has to maintain a perfect database of known-good software, without letting in any malware. Also problems with edge-cases such as adware. Also needs some way of handling private software, and self-compiled software. (which probably leads to a) or b)...) d) Third-party: All the problems of c) with more trust issues, plus iphone-ish lock-in problems. The other problem that I can see is that white-list scanners have to be much more exact on the matching (either checksums or signatures), as the malware authors will be trying to look-like authorized software. black-list scanners can afford heuristic detection, because good-software authors aren't trying to look like malware. -- Douglas Leeder Sophos Plc, The Pentagon, Abingdon Science Park, Abingdon, OX14 3YP, United Kingdom. Company Reg No 2096520. VAT Reg No GB 348 3873 20. --
| Linus Torvalds | Re: LSM conversion to static interface |
| Ingo Molnar | [patch 03/13] syslets: generic kernel bits |
| Ingo Molnar | Re: [PATCH 6/6] sched: disabled rt-bandwidth by default |
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
git: | |
| David Miller | [GIT]: Networking |
| Gregory Haskins | [RFC PATCH 00/17] virtual-bus |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
