Browse Definitions :
Definition

behavior blacklisting

Behavior blacklisting is a security method based on detecting specified suspicious actions on the part of software or human agents and blocking access accordingly. Like behavior whitelisting, behavior blacklisting is used to secure email systems against spam and phishing attempts, to protect websites, services and forums from bots and hackers and to safeguard computers from malware and hacking attempts. Breach detection systems (BDS) also rely on behavior blacklisting to maintain network security.

Content-based filtering and IP-based blacklisting, the two most common methods used to block spam, are becoming less effective as spammers have adapted their own techniques to foil them. Blacklisting can catch a significant percentage of spam missed by those methods. In a behavior-based spam filter, instead of a record of IP addresses to be blocked as known offenders, the software tracks behaviors such as sending patterns. Similarly-sent suspected mass mailings are easily blocked. Web crawling bots that may spam or vandalize websites and forums can also be blocked because of  their recognizable scripted behaviors. Heuristics-based antivirus systems are essentially a form of behavior blacklisting, helping to detect new threats and especially new variants of existing viruses.

Behavior blacklisting is especially useful on machines that have many required functions and those that are constantly changing; it can take more work to update a whitelist in such variable environments. Nevertheless, the list of allowed software and network behaviors, code executed and email addresses that could be specified on a whitelist is typically shorter than a similar compliation for a blacklist. Blacklisting behavior ensures more unblocked capabilities to begin with but must be kept up to date, and that may require more work in the long run to keep pace with changing IPs, environments and threats.

This was last updated in January 2017

Continue Reading About behavior blacklisting

SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • biometric payment

    Biometric payment is a point-of-sale (POS) technology that uses biometric authentication physical characteristics to identify the...

  • Melissa virus

    Melissa was a type of email virus that initially become an issue in early 1999.

  • Twofish

    Twofish is a symmetric-key block cipher with a block size of 128 bits and variable-length key of size 128, 192 or 256 bits.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • hard disk drive (HDD)

    A computer hard disk drive (HDD) is a non-volatile data storage device.

  • Remote Direct Memory Access (RDMA)

    Remote Direct Memory Access (RDMA) is a technology that enables two networked computers to exchange data in main memory without ...

  • storage (computer storage)

    Data storage is the collective methods and technologies that capture and retain digital information on electromagnetic, optical ...

Close