Benefit and disadvantage of blacklisting

The primary advantage of blacklisting is its simplicity. You can exclude known threats from the system and the intelligence lies with the software vendor. Its effectiveness totally depends on how often the vendor releases or updates the known threat database. From a user's point of view, all of the updates are fetched automatically. Users do not have an option to differentiate between good and bad data traffic until the software says it's bad. The major drawback of blacklisting architecture is knowing how to deal with unknown threats. For example, ransomware continues to evolve with new patterns and variants that have not been seen before.  

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.