查看: 16104|回复: 112

[技术原创] VB100报告之国内篇(斗胆改个原创,不符合标准的话再改回来吧)

发表于 2011-1-19 13:15:17 | 显示全部楼层 |阅读模式
本帖最后由 猪头无双 于 2011-1-19 23:34 编辑

翻译下VB100 12月测试中有关国产杀软的部分,翻译不准确之处以官方英文报告为准,希望VB别像AV-C的官方报告似的出现“笔误”。


ItW 100.00%               Polymorphic 100.00%
ItW (o/a) 100.00%       Trojans 93.23%
Worms & bots 97.93% False positives 0

As a Chinese solution based on the Kaspersky engine, we hoped that Keniu would handle the handful of nasties lurking in our RAP sets as we began installing the 82MB package. The set-up was fast and simple, with a very brief ‘system analysis’ phase but no messing around and no need to reboot; we soon had the simple, minimal interface up and running. With its plain colour scheme and large buttons it is fairly basic to operate, but provides a few options in an ‘advanced’ area, and proved admirably suited to running through our tests. On-demand scanning speeds were rather on the slow side, lacking the advanced tricks used by others to help things along on repeat viewings, but lag times were light and resource usage below average. On-access tests produced a few odd results, and had to be repeated, but this was fairly speedy and simple and didn’t stretch our time allowance
too much. In the on-demand tests, we saw a number of files catching the scanner out, which stuck itself into a loop and refused
to emerge. In one case even rebooting the system didn’t seem to help, with the scanner seeming to run along but failing to detect anything further. The installation had to be abandoned as irrevocably broken, and along with numerous stop-start scans, a reinstallation with several known dangerous files removed in advance was needed to get to the end of testing. After several days’ hard work we got things as finished as possible, with solid scores in the standard sets and a good start in the RAP sets, which declined fairly rapidly after the first week and remained fairly steady from there on. An early freezing of updates for submission, along with the problems encountered, should explain the lower than-expected scores. The WildList set was ably handled in the end though, and with no problems in the clean sets Keniu earns a VB100 award, having given us plenty to do to get there.

作为一款使用卡巴引擎的中国杀软,我们希望在开始安装乃们这82M安装包做PAP测试的时候能处理掉样本里隐藏的一批垃圾东西。安装过程简单迅速,中途只有个简洁的“系统扫描”,没有其他东西,也不需要重启。我们很快看到了它的简单小巧的界面,并开始测试。大按钮,简洁的布局很好操作,不过“高级功能”里边基本没神马东西,但是目前这些已经足够跑测试的了。按需扫描的速度有点低,而且没有其他工具帮助我们回过头去查看日志,但是延迟时间短,资源占用低是个特点。实时扫描测试时产生了一些奇怪的结果,而且需要重复测试,但是这属于小问题,而且重复测试也没花我们太多时间。在按需扫描中,我们发现该程序在检测某些样本的时候出现错误,直接卡住了,而且没法跳过。在其中一回,我们甚至直接重启系统,可惜没效果,此后虽然该程序还在继续跑,可惜再也没检测出神马玩意了。由于受到无可挽回的错误影响,我们不得不放弃安装,而由于有一些卡住的扫描,我们需要把某些已知的恶意文件隔离之后再次重装。经过几天的艰难工作,我们最终完成了测试,在主要测试中分数稳定,而且在RAP测试的开头有良好的表现,可惜,这表现在第一周之后就下降了,而且“稳定地”挺到PAP测试结束。由于停止收集样本的时间有些早,再加上遇到的一些问题,所以造成分数有些低。wild list测试最后完成了,而且白名单测试表现不错,所以我们给可牛这次VB100奖项。


您需要 登录 才可以下载或查看,没有帐号?快速注册



参与人数 4经验 +50 人气 +3 收起 理由
Simon_v5 + 1 你懂得。
wlx81702 + 1 支持大队原创
あ掵㊣峫淰℡ + 1 竟然没有人加人气???
皇甫暮云 + 50 原创翻译很辛苦!


 楼主| 发表于 2011-1-19 13:15:33 | 显示全部楼层
本帖最后由 猪头无双 于 2011-1-19 14:23 编辑


ItW 97.64%                  Polymorphic 43.30%
ItW (o/a) 97.64%         Trojans 88.66%
Worms & bots 92.84% False positives 6

Filseclab’s product came as a free downloadable trial from the company’s website, at 53MB for the main installer and 41MB of updates, also easily accessed. The set-up process was fast and simple, but needed a reboot to complete. The interface is fairly clear and appealing, with a decent level of configuration, although some of the options in the interface – notably adding to the depth of archives scanned – seemed to have no effect. Operation proved fairly simple, and the tests rolled along nicely, with some fairly slow speeds in the on-demand tests but average overheads and low resource use, particularly in terms of CPU cycle use. Filseclab’s on-access component seems not to fully intercept all fi le reads, although some blocking was evident, so instead we gathered all on-access data by copying files around the system. Logging also seemed only to be active if the user responded to a prompt (unless the product was set to automatically apply actions), so we ended up with various copies of our test sets, in various states of repair, scattered across the test machine. Things were somewhat simpler on demand, and didn’t take too long, so testing didn’t overrun the allotted time slot by more than half a day or so, although it was more hands-on than most ,solutions. Detection rates proved fairly decent, including a fairly good showing in the RAP sets, but as usual a fair number of WildList samples were not covered – most, but not all of them from the most recent strains of W32/Virut. We also saw a handful of false alarms in the clean sets, notably the popular VLC media player and some items from major business software house SAP. Thus Filseclab still does not quite make the grade for VB100 certifi cation, but continues to show improvement.



您需要 登录 才可以下载或查看,没有帐号?快速注册

 楼主| 发表于 2011-1-19 13:16:50 | 显示全部楼层
本帖最后由 猪头无双 于 2011-1-19 14:45 编辑


ItW 100.00%                Polymorphic 100.00%
ItW (o/a) 100.00%       Trojans 99.58%
Worms & bots 99.81% False positives 0

Qihoo’s solution is based on the BitDefender engine, and its installer comes in at 105MB. It runs through fairly quickly, with no reboot needed, and on presenting its interface offers an opportunity to join in a cloud scheme. The GUI is stylish and attractive, with some nice large buttons and plenty of good configuration options, lucidly presented, under the surface. Scanning speeds were not too slow, and on-access lag times were extremely low, although we noted that the on-access module – as with several this month – does not properly intercept read operations, rendering these measures less than fully useful. Despite this, RAM and CPU use were not much below average during the test period. On-demand scans ran smoothly, producing some very decent scores in all sets, but the on-access measure proved a little more tricky: while all fi les read were actually checked, the product did not stop them being accessed, instead slowly providing pop-ups and logging detections a while later. In the end, the fi nal sample spotted was not alerted on until more than a day after it had been opened. At least during this period some protection seemed to remain in place, and when set to delete or disinfect things were a little faster. With the good scores extending to the WildList set, and no issues emerging in the clean sets either, Qihoo earns another VB100 award.

奇虎是OEM BD的杀软,安装包105M,在呼出主界面之前会弹窗要求用户加入云社区。界面时髦,大按钮和一些很好的设置选项,再加上清晰地显示让人觉得有吸引力。检测速度不慢,实时监控延迟时间短,但我们在实时监控扫描测试过程中发现本月测试中的有些样本有读取动作,但杀软没有拦截,致使某些设置无法起作用。除此之外,CPU和内存占用比平均水平稍低。按需扫描测试结果良好,分数不错,但是实时监控有些问题:当杀软扫描所有文件的读取行为后,并木有拦截他们的下一步动作,除了过一会弹出窗口和扫描日志之外。最后一个样本并没有及时警告,而是在一天后才做出反应(汗一个)。至少这期间,某些防护措施米有起作用,当设置为清除或删除文件时才运行的稍微快了点。由于对wildlist的检测率高,白名单测试表现良好,我们授予奇虎本次VB奖项。


您需要 登录 才可以下载或查看,没有帐号?快速注册



参与人数 2人气 +2 收起 理由
小茂 + 1 加分鼓励
黑羽 + 1 翻译辛苦,加分鼓励~


 楼主| 发表于 2011-1-19 13:17:07 | 显示全部楼层
本帖最后由 猪头无双 于 2011-1-19 15:06 编辑



ItW 96.91%                  Polymorphic 73.93%
ItW (o/a) 96.91%         Trojans 51.35%
Worms & bots 76.03% False positives 0

Rising’s product arrived as a 109MB package, which installed fairly speedily, warning about a temporary loss of network connectivity while it put its components in place. After the required reboot, a configuration wizard takes the user through a number of further set-up stages. We were sad to see that the ‘Rising assistant’, aka the dancing cartoon lion that usually adorns desktops, was not in evidence this month. The interface is wordy and a little cluttered but reasonably simple to fi nd one’s way around, and enabled fairly easy running of our tests. On-demand speeds were on the slow side, but not extremely so, and on-access lags were fairly hefty, but RAM use was fairly low and CPU use not too high either. Detection rates were reasonable in the standard sets and fairly mediocre in the RAP sets, with considerable fluctuation from week to week. The clean set was handled well, but in the WildList set a number of items were not spotted, including a large swathe of rather old W32/Polip samples,

and as a result no VB100 award can be granted this month.



您需要 登录 才可以下载或查看,没有帐号?快速注册

 楼主| 发表于 2011-1-19 13:17:30 | 显示全部楼层
本帖最后由 猪头无双 于 2011-1-19 15:43 编辑



ItW 99.99%                   Polymorphic 62.79%
ItW (o/a) 99.99%           Trojans 28.48%
Worms & bots 63.24%   False positives 0

Kingsoft as usual entered both ‘Standard’ and ‘Advanced’ editions of its suite solution, and as usual there was very little difference between the two. We start with the ‘Advanced’ edition purely for alphabetical reasons, and note that the 69MB installer is significantly larger than that of the ‘Standard’ version. The installation process is rapid and simple, with no reboot required, leading into a set-up wizard which gives options on settings, the use of ‘in-the-cloud’ resources, and providing feedback. The interface is clean and clear and seems to use much nicer fonts than the previous versions tested. Navigation is simple and options are good, although translation remains a little clunky and hard to follow in places. Running through the test presented few problems, with some slowish speeds on demand, notably in the archive sets where many compression systems are unpacked in some depth, but fi le access lag times were light and system resource usage not too heavy either. Initial run through the test sets seemed to show that logging is capped at a certain size or length, but no information or options were
found regarding this, and so testing was split into chunks to ensure complete information. Detection scores were pretty low in the trojans and RAP sets, with only the set of worms and bots producing a respectable set of fi gures, but the clean sets were handled well. Stability was rock-solid throughout the tests, even under heavy stress and over samples which caused serious
problems for many products this month. All looked well until we spotted a single item in the WildList set not detected: one sample out of 2,500 replications of the latest W32/Virut strain spoiled Kingsoft’s chances of reclaiming its award despite a tester-friendly, if not overly impressive showing.



ItW 99.99%                  Polymorphic 62.64%
ItW (o/a) 99.99%         Trojans 8.30%
Worms & bots 53.35% False positives 0

As mentioned above, the ‘Standard’ edition of Kingsoft’s product is pretty much identical to the ‘Advanced’ product on the surface, but we noted the far smaller 51MB installer, and also the updates included, which appear to be several days older
than the ‘Advanced’ product. The installation process and user experience in general were light, fast, simple and clear, and
stability was again rock-solid throughout all tests, allowing us to get both products done in the same 24-hour period, on
adjacent test machines. Scanning speeds were pretty similar, but for this version access times were a little lighter, and resource consumption a fraction heavier. Detection rates were again disappointing – notably lower than the ‘Advanced’ edition, with the older updates doubtless contributing. Again, the clean sets were handled without problems, but again that single Virut sample in the WildList set put paid to any hopes of a VB100 award for the product.



您需要 登录 才可以下载或查看,没有帐号?快速注册



参与人数 1人气 +1 收起 理由
Simon_v5 + 1 给金山的。


 楼主| 发表于 2011-1-19 13:17:52 | 显示全部楼层


参与人数 10人气 +11 收起 理由
ssama + 1 根据版规,加1分以示鼓励
Simon_v5 + 2 本人金粉,仅此过来看看。
茶澈 + 1 好吧,给你
紫陈 + 1 队长
Lgwu + 1 翻译用词够专业!


发表于 2011-1-19 15:56:01 | 显示全部楼层
发表于 2011-1-19 15:59:27 | 显示全部楼层
发表于 2011-1-19 16:00:02 | 显示全部楼层
 楼主| 发表于 2011-1-19 16:00:56 | 显示全部楼层
回复 8楼 天界云涛 的帖子

您需要登录后才可以回帖 登录 | 快速注册


手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-2-5 19:57 , Processed in 0.151539 second(s), 19 queries .


快速回复 客服 返回顶部 返回列表