Reply to post: Re: Possibly shortsighted

VirusTotal wants YOU (but not you) to join its epic AV whitelist

Robert Helpmann??
Childcatcher

Re: Possibly shortsighted

I don't know exactly how AV signatures are generated...

Whitelisting actually uses a different approach than typical AV products. Similar in approach to a firewall, the default in using a whitelist is to block execution unless specifically allowed. Traditional AV products assume the process should run unless it shows up as known malware, typically through comparison with a signature (blacklists), or as the result of some sort of heuristic analysis.

Done properly, a corporate admin might use the list curated by VirusTotal as a starting point, and then de-list those apps that are not desirable for whatever reason (licensing, appropriateness to the work environment, etc.).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon