Windows 10 security hardening using device guard whitelisting and Applocker blacklisting
Rohan Durve, Ahmed Bouridane · 2017
In the estimated $2.1 trillion enterprise of cyber-crime, 95% of threats are attributed to human errors. Most of these errors concern infected attachments or following URLs to infected websites. This paper provides a low-cost solution that uses semi-automated trusted software publisher whitelisting to make it theoretically impossible for current-day malware to execute directly on Windows 10 and Windows Server 2016 systems. Specifically, the paper develops and tests Device Guard's ability to scan, auto-build and centrally deploy code integrity policies that permit only programs from trusted publishers to execute. Furthermore, the paper documents the process of hardening trusted software via AppLocker and Group Policy to prevent indirect interpretation of malicious code. The approach is based off the NSA endorsed SeLinux application whitelisting project for Linux (common in security-critical environments), but without high setup cost the typically associated with whitelisting.