Beyond Blacklisting: Cyberdefense in the Era of Advanced Persistent Threats

Aaron Beuhring, Kyle Salous · IEEE Security & Privacy · 2014

Signature-based detection is no longer an effective way to detect and block malware; whitelisting is much more effective. Whitelisting can vastly reduce an organization's attack surface, letting defenders focus on more advanced threats. It also can force attackers to use expensive exploits to execute code remotely and can make it difficult for attackers to maintain persistence. Many organizations already own tools to implement whitelisting, so the only cost is the time and effort to properly implement them.

Read the paper · More papers on PaperTik