The Endpoint Application Execution Control Scheme based on the Whitelist
Chang-Hong Kim, Jeong Hyun Yi, Jong-Bae Kim · International Journal of Control and Automation · 2015
Under the situation that existing information protection systems adopt an approach that tackles malicious codes based on already known signatures or analyzed behavior/feature, they are limited in detecting and identifying the unknown and the deformation of the malicious code. The present study, as a means of overcoming such a shortcoming, proposes a way of endpoint application control capable of more securely protecting endpoint devices (PCs) from intrusion of malicious codes and attacks through exploitation of an application or operating system vulnerability, by implementing a hybrid of technology such as whitelist-based application execution control via authentication of integrity, media access control, prevention of modification of important files, and control over IP/port attempting for process access or reverse link.