CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Application whitelisting and the importance of trusted change

Traditional endpoint security based on patching and after the fact antivirus blacklisting is drawing to a conclusion of its useful life. It’s a topic that has been in the news much of 2009 and has comprised the topic of many of my own posts. For a sampling of this topic check out any of the following posts:

That, however, is not the topic of today’s post. Today I want to talk about application whitelisting as a compliment to, or alternative for, antivirus and the importance of managing additions and updates to legitimate applications – with the least amount of operational friction. ( Read More… )

Please use the comment form and leave your thoughts!

The 451 Group Roundtable: The Real Benefits of Application Whitelisting

The 451 GroupPlease join Paul Roberts, senior analyst of enterprise security at The 451 Group, for a completely new look at Application Whitelisting in his webinar entitled “What Are The Real Benefits of Application Whitelisting: Security, Operations, Compliance?”

The webinar, sponsored by CoreTrace, will be held on October 27th at 2:00 p.m. EDT/11:00 a.m. PDT. ( Read More… )

Please use the comment form and leave your thoughts!

Memory Protection is an Important Component of Application Whitelisting Solutions

More companies than ever are looking at alternatives to blacklist antivirus. It isn’t hard to see why. Rampant botnets, endless patching, and signature distribution that simply can’t keep up with the threat are just a few of the reasons why IT and security professionals are looking for viable alternatives to protect their endpoints. Even Gartner group has said it is time to start over on desktop security. ( Read More… )

Most recent comment:   Microsoft’s Windows 7 AppLocker, a watershed moment for application whitelisting

[...] whitelisting should handle memory based attacks – I recently posted on the importance of preventing memory based attacks. The ...

Microsoft prepares for biggest patch Tuesday Ever – Endpoint security has never been worse

Microsoft prepares for largest patch tuesday everTomorrow Microsoft will release an operating system patch that represents the largest number of system fixes in Microsoft history. PCWorld gave the details in a post updated yesterday:

Microsoft says it will deliver its largest-ever number of security updates on Tuesday to fix flaws in every version of Windows, as well as Internet Explorer (IE), Office, SQL Server, important developer tools and the enterprise-grade Forefront Security client software. ( Read More… )

Most recent comment:   Application whitelisting and the importance of trusted change — CoreTrace WhiteSpace

[...] Microsoft prepares for biggest patch Tuesday Ever – Endpoint security has never been worse [...]

Top Endpoint Security Stories – September 2009

Last month I kicked off a post focusing on the top endpoint security stories in the past month. This month brought a number of endpoint security events ranging from the latest Microsoft zero-day vulnerabilities without a fix to botnet and phishing news. The theme of the month is that both individuals and corporations are simply losing the battle against online criminals when it comes to desktop security.

  • Sept 1, 2009 – IIS FTP flaw announced with exploit code
    Microsoft kicked off the month by confirming the publication of exploit code for the IIS FTP vulnerability that could allow remote code execution on affected systems. The vulnerability affected systems running the IIS web server and was particular dangerous to FTP servers that had anonymous accounts for uploads. ( Read More… )

Most recent comment:   Microsoft prepares for biggest patch Tuesday Ever – Endpoint security has never been worse — CoreTrace WhiteSpace

[...] is whether this patch will fix the critical SMB2 problem that I referenced in last week’s September Endpoint Security ...