Browse Definitions :
Definition

behavior whitelisting

Behavior whitelisting is a security method in which permissable actions within a given system are specified and all others are blocked. The method may be conducted through security software or the addition of whitelisted exceptions to a behavior blacklist.

Behavior whitelisting is used to secure websites, services and forums from bots and hackers, computers from malware and hacking attempts and email from spam and phishing attempts. Whitelisting is also used in the breach detection systems (BDS) protecting networks.

The two traditional ways of blocking spam are are content-based filtering and IP-based blacklisting. These methods are becoming less effective as spammers find ways to get around them. Blocking all behavior not on a whitelist can provide very effective security. However, it requires knowledge of what tasks and communications a system will need to perform and must be adjusted when these requirements change.

Whitelisting behavior can also be very effective in spam prevention. The method works well when the types of email sent and received are not so varied and unpredictable as to be outside of a whitelist, causing false positives. Formal email procedures can facilitate whitelisting behavior. Whitelisting commonly saves CPU and memory resources as the list of allowed behaviors is almost always smaller than is the case in a blacklist and therefore less work to scan through.

If improperly implemented, behavior whitelists can create vulnerabilities. Whitelisting is most effective where the number of required allowable functions are few and security requirements and accessibility are high. A blacklist used in this situation requires more set-up time and maintenance work to block the high volume of more varied behaviors. Blacklists also require more comprehensive and up-to-date knowledge of threats. Both methods must be implemented scrupulously to provide adequate security.

This was last updated in January 2017

Continue Reading About behavior whitelisting

SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • Melissa virus

    Melissa was a type of email virus that initially become an issue in early 1999.

  • biometric payment

    Biometric payment is a point-of-sale (POS) technology that uses biometric authentication physical characteristics to identify the...

  • Twofish

    Twofish is a symmetric-key block cipher with a block size of 128 bits and variable-length key of size 128, 192 or 256 bits.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • hard disk drive (HDD)

    A computer hard disk drive (HDD) is a non-volatile data storage device.

  • Remote Direct Memory Access (RDMA)

    Remote Direct Memory Access (RDMA) is a technology that enables two networked computers to exchange data in main memory without ...

  • storage (computer storage)

    Data storage is the collective methods and technologies that capture and retain digital information on electromagnetic, optical ...

Close