<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Application Whitelisting Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/category/application-whitelisting/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/category/application-whitelisting/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Fri, 05 Aug 2016 19:10:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>Application Whitelisting Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/category/application-whitelisting/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Ransomware Statistics and Expect Hacking on the News</title>
		<link>https://fosterinstitute.com/ransomware-statistics-and-expect-hacking-on-the-news/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Fri, 05 Aug 2016 19:10:04 +0000</pubDate>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Application Whitelisting]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[DEF CON]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[Click to Play]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[local admin]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[tech support]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog/?p=2363</guid>

					<description><![CDATA[<p>In 2015 alone, companies had to pay 325 Million in ransom to recover their data. There were 407,000 attempted ransomware attacks. These statistics confirm how organizations just don’t understand what to do to protect their company. Please spread the word… The most effective protections are all free: Use application whitelisting, click-to-play, and take away local [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/ransomware-statistics-and-expect-hacking-on-the-news/">Ransomware Statistics and Expect Hacking on the News</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In 2015 alone, companies had to pay 325 Million in ransom to recover their data. There were 407,000 attempted ransomware attacks. These statistics confirm how organizations just don’t understand what to do to protect their company. Please spread the word…<span id="more-2363"></span></p>
<p>The most effective protections are all free: Use application whitelisting, click-to-play, and take away local administrator rights. If you have any questions about any of those, please ask.</p>
<p>On a different topic, today is the first main day of DEFCON, the big hacking convention in Las Vegas. Expect the news to be full of stories about new hacks as they are announced during presentations at DEFCON. You may have seen the announcement about how hackers can defeat the new chip-and-pin protection on credit cards. More to follow…</p>
<p>The post <a href="https://fosterinstitute.com/ransomware-statistics-and-expect-hacking-on-the-news/">Ransomware Statistics and Expect Hacking on the News</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Security’s Three Essential Steps</title>
		<link>https://fosterinstitute.com/cyber-securitys-three-essential-steps/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Wed, 25 Nov 2015 19:12:03 +0000</pubDate>
				<category><![CDATA[Application Whitelisting]]></category>
		<category><![CDATA[Applying IT Patches]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Patches]]></category>
		<category><![CDATA[Preventative IT Security Breach]]></category>
		<category><![CDATA[Technology Safety]]></category>
		<category><![CDATA[Technology Safety Tips]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[application patches]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[Cyber Security Best Practices]]></category>
		<category><![CDATA[Cyber Security Breach]]></category>
		<category><![CDATA[cyber security business strategy]]></category>
		<category><![CDATA[Cyber Security Consultant]]></category>
		<category><![CDATA[cyber security expert]]></category>
		<category><![CDATA[Cyber Security Tips]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Internet Safety Tips]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[IT network security]]></category>
		<category><![CDATA[IT pros]]></category>
		<category><![CDATA[it risk management]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<category><![CDATA[it security expert]]></category>
		<category><![CDATA[IT security procedures]]></category>
		<category><![CDATA[it security review]]></category>
		<category><![CDATA[IT security training]]></category>
		<category><![CDATA[IT Support]]></category>
		<category><![CDATA[Local Admin rights]]></category>
		<category><![CDATA[patch updates]]></category>
		<category><![CDATA[program installation]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[tech support]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=2228</guid>

					<description><![CDATA[<p>In this time of gratitude, which is perhaps the most important foundation of happiness and success, it is important to thank you for helping make the world a safer place. Three controls, perhaps the most important three controls, help protect you from cyber-threats. They are: 1. Keep critical operating system and application patches up to [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/cyber-securitys-three-essential-steps/">Cyber Security’s Three Essential Steps</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In this time of gratitude, which is perhaps the most important foundation of happiness and success, it is important to thank you for helping make the world a safer place. Three controls, perhaps the most important three controls, help protect you from cyber-threats. They are:<span id="more-2228"></span></p>
<p>1. Keep critical operating system and application patches up to date, especially Flash, Java, Reader, and your browsers. Updates fix security loopholes in programs. The fear of a patch causing a program to malfunction can be reduced with proper testing, performing a staged rollout, and having a rollback plan.</p>
<p>2. Utilize Application Whitelisting. Application whitelisting allows you to specify what programs are permitted to run, such as Microsoft Office, your accounting program, and anything else your team needs for business purposes. Because of not being on the ok list, the majority of malicious software is blocked from running. The reason most companies don&#8217;t use application whitelisting is that their IT Pros know it can be a daunting process to set up and make it work well. Therefore, we can set that up for your IT pros. Why should they need to learn something when it only needs to be done once? The upkeep can be simple from then on.</p>
<p>3. Reduce the number of users with Local Admin rights as much as possible. This removes a user&#8217;s ability to install programs on their computer. As a result, it greatly hinders the ability for attackers to install malicious software too.</p>
<p>Other than implementation, none of those cost any money. You already paid for the technology. Emphasize the importance of, and support your IT Pros, as they implement these 3 powerful controls in your network. </p>
<p>Wishing you a thankful week and thank you all for remembering cyber-security as part of your main strategy for successful business operations!</p>
<p>The post <a href="https://fosterinstitute.com/cyber-securitys-three-essential-steps/">Cyber Security’s Three Essential Steps</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Stonewall, not Firewall: Use Application Whitelisting</title>
		<link>https://fosterinstitute.com/stonewall-not-firewall-use-application-whitelisting/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Mon, 31 Mar 2014 06:00:09 +0000</pubDate>
				<category><![CDATA[Application Whitelisting]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IT Professionals]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[application whitelisting]]></category>
		<category><![CDATA[it best practices]]></category>
		<category><![CDATA[it security audit]]></category>
		<category><![CDATA[IT security consultant]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1864</guid>

					<description><![CDATA[<p>Protect yourself when a user plugs in a USB device that is infected. Reduce the risk of devastation when a user accidentally clicks on a bad link. There is a program built in to Windows that can protect you, and it is one of the most important strategies to use. What to ask your IT [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/stonewall-not-firewall-use-application-whitelisting/">Stonewall, not Firewall: Use Application Whitelisting</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Protect yourself when a user plugs in a USB device that is infected. Reduce the risk of devastation when a user accidentally clicks on a bad link. There is a program built in to Windows that can protect you, and it is one of the most important strategies to use. What to ask your IT Professional is, “Do we, and if not, why not?”<span id="more-1864"></span></p>
<p>You and your IT Pros make a list of “approved programs” such as Microsoft Word, Excel, PowerPoint, IE, Firefox, Chrome, Adobe Reader, and any other programs you use. Then your computer will refuse to run any other programs – and won’t run viruses either. </p>
<p>Application whitelisting won’t necessarily block Java files, and some scripts, but it will block the majority of executables. You may want to disable Java anyway.</p>
<p>You already own the software! Microsoft includes AppLocker with your Windows OS (Windows 7: Ultimate and Enterprise) (Windows 8.1: Enterprise Only) licenses, and application restriction policies in XP. Some commercial application whitelisting tools include Bit9 Application Control, McAfee Application Control, Lumension Application Control, and Viewfinity. Other tools, such as Kaspersky, are offering application approval to their suites. The third party tools generally can make the process of implementing and maintaining application whitelisting easier for IT Pros.</p>
<p>Be prepared for possible resistance from your IT Pros, but be firm. You, and your organization’s reputation, are what will be hurt the most in a breach. Don’t let them postpone. And, if they are too ambitious, then it is imperative that you “hold them back.” Tell them that whitelisting by folder and paths is “Phase 1.” This will help them build a foundation upon which they can create even more restrictive environments.</p>
<p>The following information goes into more details, some of it technical, so it is ok to stop here and tell your IT Pros to read this part:</p>
<p>Know that application whitelisting isn&#8217;t &#8220;in demand,&#8221; nor is it widespread, though it should be. As a result, application whitelisting tools and experience is somewhat limited. When you embrace this technology, you will be on the leading edge, and not the bleeding edge.</p>
<p>Your IT professionals can configure application whitelisting solutions in such a way that upgrades and patches are allowed to run as well without specific administrator intervention.</p>
<p>AppLocker cannot block older 16-bit DOS applications, Java files, and Perl scripts. Refer to Microsoft documentation for a complete list. </p>
<p>IT Pros are very busy and realize that the process of implementing application whitelisting can be challenging. For one thing, application whitelisting can potentially cause problems if some users are not able to run the programs they need to run if the rules aren’t configured properly. Be reassured that the following information will help you be successful.</p>
<p>Remember, if a security control is difficult for IT Pros to implement, then attackers can assume the control is missing and that makes attacks that would normally be blocked more attractive. </p>
<p>Your safety-net is the audit only mode: Know that application whitelisting tools can all operate in an “audit only” mode.  That means, as you are testing your application whitelisting solution, you do not have to be concerned about generating an outage on your machines. Computers will continue to function as usual, and you will be able to preview what applications would and what applications would not have been blocked.</p>
<p>This “audit only” mode has two big benefits that will help you feel more comfortable when you implement application whitelisting. First, you have plenty of opportunities to be sure everything is configured before you engage the actual application whitelisting. Second, the audit mode is your “safety net” in the event that application causes a widespread outage and you need to “get everyone up and running again.” You can temporarily put the application whitelisting tool into the audit only mode – and everyone will be able to work until you resolve the problems.</p>
<p>The implementation of application whitelisting is simplified by wizards. The core objective of application whitelisting is to create rules that define what applications are approved to execute and which are not. Rules are what application whitelisting is all about, and the wizards can make the process much easier. But, the wizards can be evil too – tempting your IT Pros to implement too much security before the basics are handled first. Some rules are good to implement right away, other rules need to wait until a later phase.</p>
<p>Obviously, the first step is to create an inventory of all the applications on your systems that you will mark as “approved” applications. NEWT Professional is an example of a tool that can generate an inventory of installed applications, although there are many tools available.</p>
<p>First, a good strategy is for IT Pros to pick one machine, preferably a standard build that is created clean for that purpose. Then, install all the applications that any user might need to use – all the applications on this single machine. Next, use the wizards to develop a set of rules that work. You have time to repeat the modification and retesting process until you achieve the results you want and need.</p>
<p>PHASE 1: You can create rules based upon path and folder settings:  The easiest to implement, and the least secure, way to specify what applications are allowed to execute is to specify whitelisted folders by paths on the computer. The problem with this method is that an attacker can insert a devastating.exe program into an approved folder and, in that case, the executable is allowed to run. Prohibit users from being able to write files to those folders and enforce it. Block .EXE, .COM, .DLL, and the other executables but allow users to create .LNK files. </p>
<p>And that’s it!  You’ve increased security dramatically. Let this work for a few weeks, make adjustments where necessary, and feel comfortable that security is better than it was before.</p>
<p>PHASE 2: You may choose to stop after completing phase 1. If you want to add even more security, you can create rules based on software signing: With this method, you can approve programs to execute based on the company that signed the executables. For example, you may configure rules that say any executables signed by Microsoft, Adobe, etc. are allowed to execute. The idea is that attackers cannot sign the executables. Know that sometimes patches and upgrades are not signed. For example, even if you have Microsoft on your approved list, Microsoft patches may not execute properly if Microsoft didn’t sign the files. Of course, this is one of the reasons you always apply patches to a test environment, or at least a test machine, before you deploy the patches into your organization.</p>
<p>PHASE 3: You can create rules using hashes: A hash of a file is like a thumbprint; it identifies an exact file. Rules based on file hashes are more secure than the aforementioned methods of folder and certificate based rules, and hash based rules are also the most difficult for an IT Professional to maintain.  For example, the Executable(s) for Microsoft Excel can be approved by hashes of the executables. But what happens when a patch changes those files? The executables won’t match the hash and the application will stop working. Again, if you are testing the patching process, which is so important anyway, you would catch this problem before it affected any of your users anyway. Additionally, some of the commercial tools automatically update the hashes in your rules for you based on expected patches and upgrades. Avoid feeling intimidated by the hash method – it can be very secure – but  you may find that maintaining the rules may be over-burdensome. </p>
<p>Refer to Microsoft’s documentation of how to use GPOs to deploy the rules based on departments, roles, etc. Remember that commercial tools can help automate this entire process. </p>
<p>Though application whitelisting is still developing, it is mature enough to become a powerful part of your cyber-security arsenal.</p>
<p>Your knowledge and experiences will help other administrators too. I encourage you to post your experiences to below&#8230;</p>
<p>The post <a href="https://fosterinstitute.com/stonewall-not-firewall-use-application-whitelisting/">Stonewall, not Firewall: Use Application Whitelisting</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
