Beyond Blacklisting: Cyberdefense in the Era of Advanced Persistent Threats
Aaron Beuhring, Kyle Salous · IEEE Security & Privacy · 2014
Signature-based detection is no longer an effective way to detect and block malware; whitelisting is much more effective. Whitelisting can vastly reduce an organization's attack surface, letting defenders focus on more advanced threats. It also can force attackers to use expensive exploits to execute code remotely and can make it difficult for attackers to maintain persistence. Many organizations already own tools to implement whitelisting, so the only cost is the time and effort to properly implement them.