If someone adds a layer to OS's file system such as only the know good white list app, exe, .so, .dll, .sys files with complete crypto-hash signatures are allowed to run in "lockdown" mode.
Everything else are reported and blocked.
Would it be enough to prevent such worm?
It would be interesting exercise to take an old exploitable OS (Win XP, or 10 years old Linux with known issue) add such layer to it. Put it on internet as honeypot and see what other kind of inflections it might get.