Browse Definitions :
Definition

behavior blacklisting

Contributor(s): Matthew Haughn

Behavior blacklisting is a security method based on detecting specified suspicious actions on the part of software or human agents and blocking access accordingly. Like behavior whitelisting, behavior blacklisting is used to secure email systems against spam and phishing attempts, to protect websites, services and forums from bots and hackers and to safeguard computers from malware and hacking attempts. Breach detection systems (BDS) also rely on behavior blacklisting to maintain network security.

Content-based filtering and IP-based blacklisting, the two most common methods used to block spam, are becoming less effective as spammers have adapted their own techniques to foil them. Blacklisting can catch a significant percentage of spam missed by those methods. In a behavior-based spam filter, instead of a record of IP addresses to be blocked as known offenders, the software tracks behaviors such as sending patterns. Similarly-sent suspected mass mailings are easily blocked. Web crawling bots that may spam or vandalize websites and forums can also be blocked because of  their recognizable scripted behaviors. Heuristics-based antivirus systems are essentially a form of behavior blacklisting, helping to detect new threats and especially new variants of existing viruses.

Behavior blacklisting is especially useful on machines that have many required functions and those that are constantly changing; it can take more work to update a whitelist in such variable environments. Nevertheless, the list of allowed software and network behaviors, code executed and email addresses that could be specified on a whitelist is typically shorter than a similar compliation for a blacklist. Blacklisting behavior ensures more unblocked capabilities to begin with but must be kept up to date, and that may require more work in the long run to keep pace with changing IPs, environments and threats.

This was last updated in January 2017

Continue Reading About behavior blacklisting

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • PCI DSS (Payment Card Industry Data Security Standard)

    The Payment Card Industry Data Security Standard (PCI DSS) is a widely accepted set of policies and procedures intended to ...

  • risk management

    Risk management is the process of identifying, assessing and controlling threats to an organization's capital and earnings.

  • compliance framework

    A compliance framework is a structured set of guidelines that details an organization's processes for maintaining accordance with...

SearchSecurity

  • Trojan horse (computing)

    In computing, a Trojan horse is a program downloaded and installed on a computer that appears harmless, but is, in fact, ...

  • identity theft

    Identity theft, also known as identity fraud, is a crime in which an imposter obtains key pieces of personally identifiable ...

  • DNS over HTTPS (DoH)

    DNS over HTTPS (DoH) is a relatively new protocol that encrypts domain name system traffic by passing DNS queries through a ...

SearchHealthIT

  • telemedicine (telehealth)

    Telemedicine is the remote delivery of healthcare services, such as health assessments or consultations, over the ...

  • Project Nightingale

    Project Nightingale is a controversial partnership between Google and Ascension, the second largest health system in the United ...

  • medical practice management (MPM) software

    Medical practice management (MPM) software is a collection of computerized services used by healthcare professionals and ...

SearchDisasterRecovery

SearchStorage

  • M.2 SSD

    An M.2 SSD is a solid-state drive (SSD) that conforms to a computer industry specification and is used in internally mounted ...

  • kilobyte (KB or Kbyte)

    A kilobyte (KB or Kbyte) is a unit of measurement for computer memory or data storage used by mathematics and computer science ...

  • virtual memory

    Virtual memory is a memory management capability of an operating system (OS) that uses hardware and software to allow a computer ...

Close