Terms often used interchangeably that have a big impact on your security

  • Application Control typically refers to ‘fuzzy’ application whitelisting technologies which place trust in software packages for the purposes of software management.

  • Application Whitelisting refers to ‘strict’ application whitelisting technologies which place trust in files for the purposes of security.

Application Control

Application Control technologies may allow attackers to slip through the gaps. By treating software as ‘packages’ rather than individual files, the trusted software often requires the ability to run any file of it’s choosing. This allows attackers to run malicious code if the application itself is compromised, which commonly occurs through social engineering attacks.

 

Application-Control-1

 

Application Whitelisting

Application Whitelisting technologies uniquely identify every file and application library as a unique item, regardless of what software it belongs to. If any file is modified or tampered with, the file is prevented execution. This very effectively prevents attackers from running malicious code on a system and significantly increases the ability of organisations to identify attempts of compromise.

 

Application-Whitelisting-1

 

 

TLDR; Application Whitelisting places trust in files not software packages, therefore providing a significant security benefit.

Learn More