Norton 2009 tackles whitelisting

Symantec has adopted whitelising techniques in an effort to dramatically improve the performance of its upcoming Norton 2009 security suite, according to the company's vice president of consumer engineering, Rowan Trollope.

In order to watch video content you need to enable javascript and install Flash player version 8 or above.

Trollope admitted that poor performance was the main reason Norton Internet Security customers abandoned previous versions of the product. In the next version, he explained, a "whitelisting approach" significantly reduced the amount of time scanning files that are known to be safe.

"It does use whitelisting as an approach, but it really focuses on the performance gains we can get by not having to scan things on the whitelist," he said.

The concept of using whitelisting in security is nothing new. Whitelists, for example, are used by airlines to determine whether a passenger can board. If you have a boarding pass, you're allowed to take a seat but if you don't, you're not. A blacklist, commonly used in signature-based antivirus, works the opposite way by creating a list of unwanted files, such as known malware, to prevent entry.

Cisco's chief security officer John Stewart earlier this year complained that antivirus "doesn't work", and called for whitelists to become more common. McAfee's CEO Dave De Walt a few weeks later claimed that malware volumes had pushed blacklisting to its architectural limits and suggested that whitelists held "very strong" promise in meeting this challenge.

While enterprises sometimes use whitelisting technologies, such as hosted intrusion prevention systems (HIPS), to combat zero-day threats, whitelists are yet to find a place in consumer security. However, Trollope pointed out that Symantec is using the whitelist to improve performance, not to prevent malware being installed on a PC.

"We are looking at all of our 55 million customers' systems ... and base the whitelist on which applications are very common," he said.

"We know that an application installed on less than 10 systems is most likely malicious. Unless you're a software engineer ... it's unlikely that anyone has a piece of software that runs only on 10 systems," Trollope told ZDNet.com.au.

"Legitimate application writers are looking to get large distribution of their software; malware writers are looking to limit it so they can stay under the radar of signature-based malware vendors," he added.

Advertisement

Talkback 1 comments

    Possible error in the articleAdam Nelson -- 06/09/08

    "Cisco's chief security officer John Stewart"

    John not only a satire news brodcaster. But works for cisco too!


Latest Videos

Blogs

  • Juha Saarinen TelstraUnClear
    Telstra's New Zealand arm TelstraClear is one strange company ...
  • Array E-health too unsexy for COAG
    There will always be something more politically sexy than e-health for state governments, meaning the National E-Health Transition Authority's business case for a national electronic medical record might just sit on the shelf gathering dust forever.
  • Array Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • More blogs »

Tags

Back to top

Featured