This document discusses the failure of current endpoint protection platforms and the opportunity for a new "default deny" approach using lightweight container technology. It summarizes research from Gartner identifying emerging techniques like application control, malware sandboxing, and software attestation that could enable a default deny paradigm. Comodo's new Advanced Endpoint Protection solution is presented as an example of next-generation protection that implements these techniques using containment to combine application control, sandboxing, and attestation. It aims to block even unknown threats by considering anything unknown as untrusted and contained until assessment.