Coming: A Change in Tactics in Malware Battle New Jersey

To keep up with the criminals, antivirus companies plan a major shift in approach, called 'whitelisting'.

Local Companies

PC Computer System
(201) 222-0777
465 Central Ave
Jersey City, NJ
ELWC
(908) 212-7873
PO Box 483
Piscataway, NJ
Internet Presentations Inc
(201) 795-1555
880 Bergen Ave
Jersey City, NJ
Ny Internet Med
(201) 626-3818
111 Town Square Pl
Jersey City, NJ
Xcite Net
(201) 653-8954
111 Town Square Pl
Jersey City, NJ
XI SOFTWARE SYSTEMS
(201) 420-4098
880 Bergen Ave Ste 305
Jersey City, NJ
Salespresence Inc
(201) 420-0055
60 Erie St
Jersey City, NJ
Internet Connec
(201) 659-8400
545 Washington Blvd
Jersey City, NJ
Carroll Communications
732-751-0101
5133 West Hurley Pond Rd.
Farmingdale, NJ
Fusion Design Inc
(201) 434-7000
66 York St
Jersey City, NJ

As a vast flood of new malware threatens to overwhelm antivirus software, security companies have begun changing how their programs protect PCs. To avoid being left in the dust by the crooks, companies plan to turn the tables on them by allowing only known good programs to run.

The technique, known as whitelisting, could help protect your computer. But though some security apps already use this approach (seethe next pagefor our look at a few free downloads), it can also make using your PC a huge annoyance.

"Whitelisting is probably at the top of the list for what the industry needs to move towards," says Jeff Aliber, senior director of product marketing with antivirus maker Kaspersky Labs.

For Kaspersky and other antivirus companies, the ocean of malicious software in circulation today may mean that just tracking known good software will be easier than trying to keep tabs on all the bad stuff. For example, Symantec, which has been pushing for an industry shift to whitelists since last year, anonymously tracks new applications that appear on PCs participating in its Norton Community Watch program. During one week last November, more than half of the 54,000 new executables reported by Community Watch were malicious, says Carey Nachenberg, a vice president and developer with Symantec Research Labs.

In the face of that sobering reality, Kaspersky this summer will release its first consumer antivirus products that bring in whitelists. It will use lists from Bit9, a whitelisting company that maintains a 6.3 billion-strong list of known good applications. The new Kaspersky applications won't automatically block programs not on the Bit9 list, but instead will focus scanning resources on those programs that Bit9 doesn't recognize. Theoretically, that could allow for more careful scrutiny of unknown files with less risk of false alerts.

But that huge number in Bit9's list--6.3 billion--highlights the risk of using whitelists to fully block unknown apps. Nobody has a full list of all good software, so you can't block everything not on a list without eventually blocking some great but relatively unknown programs. And displaying a pop-up that asks you to decide whether an unknown app is okay to run ensures that you'll eventually make the wrong call and break your software or even your system. Most antivirus companies rightly make every effort to minimize the number of alerts that ask us to make a decision; an overreliance on whitelists could roll back those improvements.

Community-Based Security

Symantec says it's looking at one possible solution, which is to bring in its community, where it checks to see if other Norton users have a given program installed. The company reasons that if, say,a hundred thousand people are running a particular app, with no reports to Symantec that it's a threat, then it's likely safe. Nachenberg says the company is experimenting with this kind of reputation-based system to add to its products over the next few years.

And then there's the big question: Who maintains the list? If every antivirus company maintains its own, as Symantec says it wants to, small developers would have to submit their cool new downloads to at least five different organizations--and gain approval from all of them. But an alternative to that prospect isa central list available to everyone, maintained by the government or a neutral, open organization.

"I think a centralized whitelist would be beneficial to everyone," says Kevin Beaver, an independent security consultant with Principle Logic who has written a number of books on computer safety.

"The problem is," he adds,"politics will likely get in the way of anything productive, especially when the big antimalware players want to maintain control. I think we'll see something like[a centralized whitelist]within the next few years, but this type of collaboration can't be pulled together overnight."

Free Downloads for Whitelist Protection

In the meantime, a number of free security tools already use a whitelist approach to protect PCs. However, in using them you'll typically get many pop-ups that may require a good deal of technical knowledge to interpret--a hassle that makes clear the challenge to the major antivirus companies. But if you're willing to deal with the interruptions--which can includereversing a mistaken decision--these downloads can bring strong protection against malware.

First, the Comodo Firewall Pro Free offers full whitelist-style program blocking in addition to its firewall; it works on Windows XP and Vista. Once installed, the program displays an alert when an unknown program runs, and you'll have to choose to allow or deny the new app. Comodo already knows about popular apps such as Firefox and won't display alerts for them, and also provides some good information in the pop-ups to help you decide whether to let a program take a particular action.

It also has a learning mode that automatically creates rules allowing everything on your system to run while it's enabled. This mode can help cut down on the pop-ups when you first install the program, but you should enable it only if you're sure your system is clean.

During installation, the free version prompts you to install a browser search toolbar and change your home page (a $40/year paid option offers remote desktop support for cleaning malware infections). You can opt out of the toolbar installation and browser changes, and can also choose to install only the capable firewall without the whitelisting protection.

Online Armor Free

Like Comodo Firewall Pro, Online Armor Free provides both a firewall and a whitelist approach to program security for Windows NT, 2000, and XP. It does not show pop-ups for many known good programs, and it scans all your installed programs when it first runs so you can quickly tell it what to do with apps it doesn't know about.

When it does alert you to a new, unknown program, Online Armor's popups are informative but generally somewhat harder to decipher than those from Comodo. However, Online Armor goes beyond Comodo with a 'Safer' mode that allows apps to run, but with stripped-down privileges. Safer mode can work well for at-risk applications like Web browsers or e-mail programs, as it pulls administrator rights from such apps and prevents them from making deep system changes. (Read more about admin rights and their risks.)

Online Armor Free has a learning mode, but you'll have to manually check for program updates with the free version. A $40/year paid option adds automatic updates along with online banking protection and other features.

If you're happy with your firewall and just want a dedicated whitelisting security program, System Safety Monitor Free Edition makes for both a quick download (3.25MB) and a quick installation under Windows XP, 2000, 98, and Me. You can set an advanced level of rules for what any given program can or can't do on your system. On the downside, you'll get an alert for almost every program, including common Web browsers, and the information in the pop-ups can be hard to figure out for nonexperts. It's easy to quickly change a mistaken decision, though.

Finally, if you want to access a whitelist with minimal impact, the Fileadvisor Windows Explorer extension, from Bit9 adds a right-click option to check any given file or program against the company's own online whitelist. You'll need to register with the site to get search results (which display in your browser), but since it doesn't block anything, you don't run any risk by using it.

For other free whitelist download recommendations, head to posts on the Wilders Security Forums and CastleCops, two excellent if somewhat technical security resources.

As these apps show, whitelist security may be a tool for techies today. But soon it'll be de rigeur in the battle against malware.

Featured Local Company

PC Computer System

(201) 222-0777
465 Central Ave
Jersey City, NJ

Regional Articles
- Coming: A Change in Tactics in Malware Battle Absecon NJ
- Coming: A Change in Tactics in Malware Battle Asbury Park NJ
- Coming: A Change in Tactics in Malware Battle Atlantic City NJ
- Coming: A Change in Tactics in Malware Battle Barnegat NJ
- Coming: A Change in Tactics in Malware Battle Basking Ridge NJ
- Coming: A Change in Tactics in Malware Battle Bayonne NJ
- Coming: A Change in Tactics in Malware Battle Bayville NJ
- Coming: A Change in Tactics in Malware Battle Belle Mead NJ
- Coming: A Change in Tactics in Malware Battle Belleville NJ
- Coming: A Change in Tactics in Malware Battle Belmar NJ
- Coming: A Change in Tactics in Malware Battle Bergenfield NJ
- Coming: A Change in Tactics in Malware Battle Blackwood NJ
- Coming: A Change in Tactics in Malware Battle Bloomfield NJ
- Coming: A Change in Tactics in Malware Battle Boonton NJ
- Coming: A Change in Tactics in Malware Battle Bordentown NJ
- Coming: A Change in Tactics in Malware Battle Brick NJ
- Coming: A Change in Tactics in Malware Battle Bridgeton NJ
- Coming: A Change in Tactics in Malware Battle Bridgewater NJ
- Coming: A Change in Tactics in Malware Battle Browns Mills NJ
- Coming: A Change in Tactics in Malware Battle Burlington NJ
- Coming: A Change in Tactics in Malware Battle Caldwell NJ
- Coming: A Change in Tactics in Malware Battle Camden NJ
- Coming: A Change in Tactics in Malware Battle Cape May Court House NJ
- Coming: A Change in Tactics in Malware Battle Cape May NJ
- Coming: A Change in Tactics in Malware Battle Carteret NJ
- Coming: A Change in Tactics in Malware Battle Cherry Hill NJ
- Coming: A Change in Tactics in Malware Battle Clark NJ
- Coming: A Change in Tactics in Malware Battle Clementon NJ
- Coming: A Change in Tactics in Malware Battle Cliffside Park NJ
- Coming: A Change in Tactics in Malware Battle Clifton NJ
- Coming: A Change in Tactics in Malware Battle Collingswood NJ
- Coming: A Change in Tactics in Malware Battle Colonia NJ
- Coming: A Change in Tactics in Malware Battle Cranford NJ
- Coming: A Change in Tactics in Malware Battle Denville NJ
- Coming: A Change in Tactics in Malware Battle Deptford NJ
- Coming: A Change in Tactics in Malware Battle Dumont NJ
- Coming: A Change in Tactics in Malware Battle East Brunswick NJ
- Coming: A Change in Tactics in Malware Battle East Orange NJ
- Coming: A Change in Tactics in Malware Battle Eatontown NJ
- Coming: A Change in Tactics in Malware Battle Edison NJ
- Coming: A Change in Tactics in Malware Battle Egg Harbor Township NJ
- Coming: A Change in Tactics in Malware Battle Elizabeth NJ
- Coming: A Change in Tactics in Malware Battle Englewood NJ
- Coming: A Change in Tactics in Malware Battle Englishtown NJ
- Coming: A Change in Tactics in Malware Battle Ewing NJ
- Coming: A Change in Tactics in Malware Battle Fair Lawn NJ
- Coming: A Change in Tactics in Malware Battle Flemington NJ
- Coming: A Change in Tactics in Malware Battle Forked River NJ
- Coming: A Change in Tactics in Malware Battle Fort Lee NJ
- Coming: A Change in Tactics in Malware Battle Freehold NJ
- Coming: A Change in Tactics in Malware Battle Garfield NJ
- Coming: A Change in Tactics in Malware Battle Glassboro NJ
- Coming: A Change in Tactics in Malware Battle Hackensack NJ
- Coming: A Change in Tactics in Malware Battle Hackettstown NJ
- Coming: A Change in Tactics in Malware Battle Haddon Township NJ
- Coming: A Change in Tactics in Malware Battle Haddonfield NJ
- Coming: A Change in Tactics in Malware Battle Haledon NJ
- Coming: A Change in Tactics in Malware Battle Hammonton NJ
- Coming: A Change in Tactics in Malware Battle Hazlet NJ
- Coming: A Change in Tactics in Malware Battle Hightstown NJ
- Coming: A Change in Tactics in Malware Battle Hillside NJ
- Coming: A Change in Tactics in Malware Battle Hoboken NJ
- Coming: A Change in Tactics in Malware Battle Holmdel NJ
- Coming: A Change in Tactics in Malware Battle Howell NJ
- Coming: A Change in Tactics in Malware Battle Irvington NJ
- Coming: A Change in Tactics in Malware Battle Iselin NJ
- Coming: A Change in Tactics in Malware Battle Jackson NJ
- Coming: A Change in Tactics in Malware Battle Jersey City NJ
- Coming: A Change in Tactics in Malware Battle Kearny NJ
- Coming: A Change in Tactics in Malware Battle Keyport NJ
- Coming: A Change in Tactics in Malware Battle Lakehurst NJ
- Coming: A Change in Tactics in Malware Battle Lakewood NJ
- Coming: A Change in Tactics in Malware Battle Linden NJ
- Coming: A Change in Tactics in Malware Battle Livingston NJ
- Coming: A Change in Tactics in Malware Battle Long Branch NJ
- Coming: A Change in Tactics in Malware Battle Lyndhurst NJ
- Coming: A Change in Tactics in Malware Battle Madison NJ
- Coming: A Change in Tactics in Malware Battle Mahwah NJ
- Coming: A Change in Tactics in Malware Battle Manahawkin NJ
- Coming: A Change in Tactics in Malware Battle Manchester Township NJ
- Coming: A Change in Tactics in Malware Battle Maple Shade NJ
- Coming: A Change in Tactics in Malware Battle Maplewood NJ
- Coming: A Change in Tactics in Malware Battle Marlboro NJ
- Coming: A Change in Tactics in Malware Battle Marlton NJ
- Coming: A Change in Tactics in Malware Battle Matawan NJ
- Coming: A Change in Tactics in Malware Battle Mays Landing NJ
- Coming: A Change in Tactics in Malware Battle Medford NJ
- Coming: A Change in Tactics in Malware Battle Merchantville NJ
- Coming: A Change in Tactics in Malware Battle Metuchen NJ
- Coming: A Change in Tactics in Malware Battle Middletown NJ
- Coming: A Change in Tactics in Malware Battle Millville NJ
- Coming: A Change in Tactics in Malware Battle Monroe Township NJ
- Coming: A Change in Tactics in Malware Battle Montclair NJ
- Coming: A Change in Tactics in Malware Battle Moorestown NJ
- Coming: A Change in Tactics in Malware Battle Morganville NJ
- Coming: A Change in Tactics in Malware Battle Morris Plains NJ
- Coming: A Change in Tactics in Malware Battle Morristown NJ
- Coming: A Change in Tactics in Malware Battle Mount Holly NJ
- Coming: A Change in Tactics in Malware Battle Mount Laurel NJ
- Coming: A Change in Tactics in Malware Battle Neptune NJ
- Coming: A Change in Tactics in Malware Battle New Brunswick NJ
- Coming: A Change in Tactics in Malware Battle Newark NJ
- Coming: A Change in Tactics in Malware Battle Newton NJ
- Coming: A Change in Tactics in Malware Battle North Arlington NJ
- Coming: A Change in Tactics in Malware Battle North Bergen NJ
- Coming: A Change in Tactics in Malware Battle North Brunswick NJ
- Coming: A Change in Tactics in Malware Battle Nutley NJ
- Coming: A Change in Tactics in Malware Battle Ocean City NJ
- Coming: A Change in Tactics in Malware Battle Old Bridge NJ
- Coming: A Change in Tactics in Malware Battle Orange NJ
- Coming: A Change in Tactics in Malware Battle Palisades Park NJ
- Coming: A Change in Tactics in Malware Battle Paramus NJ
- Coming: A Change in Tactics in Malware Battle Parlin NJ
- Coming: A Change in Tactics in Malware Battle Parsippany NJ
- Coming: A Change in Tactics in Malware Battle Passaic NJ
- Coming: A Change in Tactics in Malware Battle Paterson NJ
- Coming: A Change in Tactics in Malware Battle Pennsauken NJ
- Coming: A Change in Tactics in Malware Battle Perth Amboy NJ
- Coming: A Change in Tactics in Malware Battle Phillipsburg NJ
- Coming: A Change in Tactics in Malware Battle Piscataway NJ
- Coming: A Change in Tactics in Malware Battle Plainfield NJ
- Coming: A Change in Tactics in Malware Battle Plainsboro NJ
- Coming: A Change in Tactics in Malware Battle Pleasantville NJ
- Coming: A Change in Tactics in Malware Battle Point Pleasant Beach NJ
- Coming: A Change in Tactics in Malware Battle Princeton Junction NJ
- Coming: A Change in Tactics in Malware Battle Princeton NJ
- Coming: A Change in Tactics in Malware Battle Rahway NJ
- Coming: A Change in Tactics in Malware Battle Ramsey NJ
- Coming: A Change in Tactics in Malware Battle Red Bank NJ
- Coming: A Change in Tactics in Malware Battle Rockaway NJ
- Coming: A Change in Tactics in Malware Battle Rutherford NJ
- Coming: A Change in Tactics in Malware Battle Sayreville NJ
- Coming: A Change in Tactics in Malware Battle Scotch Plains NJ
- Coming: A Change in Tactics in Malware Battle Secaucus NJ
- Coming: A Change in Tactics in Malware Battle Sewell NJ
- Coming: A Change in Tactics in Malware Battle Sicklerville NJ
- Coming: A Change in Tactics in Malware Battle Somerset NJ
- Coming: A Change in Tactics in Malware Battle Somerville NJ
- Coming: A Change in Tactics in Malware Battle South Amboy NJ
- Coming: A Change in Tactics in Malware Battle South Orange NJ
- Coming: A Change in Tactics in Malware Battle South Plainfield NJ
- Coming: A Change in Tactics in Malware Battle South River NJ
- Coming: A Change in Tactics in Malware Battle Summit NJ
- Coming: A Change in Tactics in Malware Battle Teaneck NJ
- Coming: A Change in Tactics in Malware Battle Toms River NJ
- Coming: A Change in Tactics in Malware Battle Trenton NJ
- Coming: A Change in Tactics in Malware Battle Tuckerton NJ
- Coming: A Change in Tactics in Malware Battle Union City NJ
- Coming: A Change in Tactics in Malware Battle Union NJ
- Coming: A Change in Tactics in Malware Battle Vincentown NJ
- Coming: A Change in Tactics in Malware Battle Vineland NJ
- Coming: A Change in Tactics in Malware Battle Voorhees NJ
- Coming: A Change in Tactics in Malware Battle Wayne NJ
- Coming: A Change in Tactics in Malware Battle West Milford NJ
- Coming: A Change in Tactics in Malware Battle West New York NJ
- Coming: A Change in Tactics in Malware Battle West Orange NJ
- Coming: A Change in Tactics in Malware Battle Westfield NJ
- Coming: A Change in Tactics in Malware Battle Westwood NJ
- Coming: A Change in Tactics in Malware Battle Williamstown NJ
- Coming: A Change in Tactics in Malware Battle Willingboro NJ
- Coming: A Change in Tactics in Malware Battle Wyckoff NJ
Related Articles

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History