Application control for malware protection

Vanja Svacjer Sophos

Traditionally, protection against malicious software has relied on the known bad characteristic of file structure, functionality in the code and the exhibited behaviour. Soon after traditional anti-virus vendors started dealing with potentially unwanted applications (PUA), it became clear that the concept can be easily extended to other, fully legitimate applications that may cause decrease in productivity or provide a vector for information leakage (IM clients, VoIP programs and games). If the 'detect and authorise' approach can be applied to some, why not to all applications?

As it is fairly safe to say that the number of existing malicious programs is approaching a million, the inevitable question comes to mind - would it be possible to provide comprehensive protection against malicious software by detecting a set of known good characteristics of file structure, functionality and behaviour instead of the know bad ones? The concept is already used by client firewalls when blocking outgoing network requests and limiting the behaviour of an unauthorised program.

At first, this approach seems very appealing, but it brings its own set of problems, concentrated around completeness of the detection set, management of new application versions and updates, verification of integrity of the controlled applications and reliance on the end-user to make an informed decision.

This paper investigates the feasibility of using application control for malware protection. The concept is evaluated by looking into known classes of malware, a set of representative samples and the results of the applying application control on the quality of protection against the chosen sample set. The paper also investigates other problems of application control implementation and discusses potential solutions.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Career Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 190,982 registered users.