Skip the navigation
Review

Review: Whitelisting security software comes of age

Remarkably good products from five vendors show that whitelisting may be the new best defense against modern malware.

By Roger A. Grimes
November 4, 2009 06:13 AM ET

InfoWorld - Whitelisting security has always taken a backseat to blacklisting approaches. After all, when there is far more good software running on computers and networks than bad software, it's just easier to block the bad than to approve all the good. But that was then, and this is now.

In 2009, the computer security defense world quietly marked a momentous threshold that should have us all looking anew at the value of whitelisting. Last year, the number of unique malicious programs and variants that were created outstripped all the legitimate software published in the world, straining the accuracy of anti-virus solutions like never before. It's a disturbing fact that suggests whitelisting is now more suitable as a primary security defense than traditional anti-virus scanners, which are really nothing more than blacklisting programs.

[ Read the individual reviews of Bit9 Parity Suite, CoreTrace Bouncer, Lumension Application Control, McAfee Application Control, and SignaCert Enterprise Trust Services. Compare the capabilities of Microsoft AppLocker, the whitelisting feature included in Windows 7 and Windows Server 2008 R2. ]

Now for some good news: Just as whitelisting may be finding a receptive audience, a number of whitelisting solutions are proving to be mature, capable, and manageable enough to provide significant protection while still giving trustworthy users room to breathe. Nor are today's whitelisting programs limited to locking down desktops to prevent malware executions -- they're also useful for software configuration and licensing compliance and regulatory auditing.

With these benefits in mind, InfoWorld tested six enterprise-grade whitelisting programs, otherwise known as application control programs. The reviewed products include Bit9 Parity, CoreTrace Bouncer, Lumension Application Control (formerly SecureWave Sanctuary), McAfee Application Control (formerly Solidcore S3 Control), and SignaCert Enterprise Trust Services. We also tested Microsoft AppLocker, the application whitelisting feature built into Windows 7 and Windows Server 2008 R2. In all cases, testing was done using the product's Windows clients, though one or two of the products also support Linux or Solaris or Mac OS X.

In a rare occurrence for a product comparison of this scope, all the products came out pretty well. The overall conclusion is that any of the reviewed products would help you reduce real and measurable security risk. A few are borderline excellent (scoring in the high 8s on InfoWorld's 10-point scale), and one, Bit9's Parity, is not only the clear frontrunner (with a score of 9.4) but a likely candidate for InfoWorld's Technology of the Year Award. Oh, to have such choices.

Next page: New world order

InfoWorld Test Center comparison chart -- whitelisting security packages
Source: InfoWorld Test Center
Originally published on www.infoworld.com. Click here to read the original story.
Reprinted with permission from InfoWorld. Story copyright 2010 InfoWorld Media Group, Inc. All rights reserved.

Software

Additional Resources
Advancing Knowledge Sharing with Google: The LSNC Story
WEBCAST
In the modern work environment, knowledge sharing has become paramount to organizational success, given the geographic dispersion, mobility, and information overload. During this session, Legal Services of Northern California (LSNC) will discuss their recent knowledge sharing transformation. With employees across 14 offices, servicing one-third of California, and having to access information across a million documents, the challenge was daunting. To address this, LSNC tapped Google's expertise on enterprise search and cloud computing, and deployed a knowledge-content system.
Cost-Effective Virtualization Security
WHITE PAPER
Trend Micro(tm) Virtualization Security solutions deliver advanced security software to protect operating systems, applications and data on virtual and cloud servers to help ensure compliance, while allowing higher server consolidation rates, and maximizing performance and operational flexibility. With Trend Micro software deployed on your physical servers and virtual machines, your IT infrastructure receives comprehensive and integrated protection.
The Laptop Dilemma: How to Maximize Productivity and Lower the Burden on IT
WHITE PAPER
New era of mobile computing creates opportunities for remote productivity while next-generation, industry-standard technologies address management and data security. Read more in this white paper.
What People Are Saying
Security White Papers
Backup and Disaster Recovery eGuide
As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
Read Now.
Windows 7 Migration Made Easier with Desktop Virtualization
Read Now.
Virtualization 2.0: The Desktop Revolution
Read Now.
Securing Data in the Cloud
This document is intended to give a broad overview of our security policies, processes and practices.
All Security White Papers
Security Webcasts
Desktop virtualization keys innovation drive
View now.
Survival Guide: Overcoming the Obstacles to Effective Risk Management
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
How to cut software management costs and avoid over-spending in the future
View now!
Get a $20 Amazon Gift Card - Just watch a Demo
View now!
All Security Webcasts
IT Jobs