查看: 1848|回复: 4
收起左侧

[资讯] Consumer AV/EPP Comparative Analysis - Exploit-Evasion Defenses

[复制链接]
firefox3
发表于 2012-11-3 12:22:27 | 显示全部楼层 |阅读模式
As security products improve their abilities to detect cyber threats, criminals react by attempting to conceal malware by packaging it with a variety of technologies. This group test report analyzes some of the common methods used by cyber criminals to circumvent or evade detection by consumer anti-malware or Endpoint Protection Products (EPP).

Cyber criminals do not just develop one attack and move on. Rather, they seek to make their software usable for as long as possible. Evasion techniques allow known threats to circumvent detection by security products.

NSS Labs tested 13 popular endpoint security suites to measure their effectiveness in protecting Windows computers against evasions. Understanding which products have coverage for the various evasion techniques is an important indicator of product quality of which consumers need to be aware. Consumers, and enterprises that have implemented a bring your own device (BYOD) policy, who seek protection from attacks against desktop PCs and laptops should closely examine results from this test.  

The NSS Labs 2012 Exploit Protection Comparative Analysis Report has already demonstrated weaknesses in the abilities of most security products to detect a wide range of exploits. Evasion techniques provide an additional means for attackers to deliver the same exploits to the endpoint, and EPP products have traditionally proved poor at handling such techniques. However, this test indicates that vendors are beginning to take this threat seriously, since anti-evasion protection is greatly improved compared with previous tests.

The chart below shows ranking in terms of the absolute number of test cases passed. It should be noted that products that block on execution, but not on download, provide better protection for consumers than products that miss packed or compressed samples on execution.



Key Findings
Most vendors have dramatically improved their coverage for the basic evasions used in our testing as compared to NSS Labs testing in 2010.
Executable compressors are still problematic for some vendors.
Most vendors are not scanning standard compressors on download, and some are not scanning compressed executable payloads on download.
Microsoft exhibited the strongest anti-evasion capabilities.
Recommendations
Since patching helps to mitigate the impact of evasions, consumers should always keep their software current in addition to deploying endpoint security.
Consumers using products that do not inspect compressed software on download should contact their vendors for assistance in configuring their software to scan compressed files on download.
The most current browsers help block some malicious downloads, and should be used in favor of older browsers.
Tested Products
Avast Pro Antivirus 7 7.0.1466
AVG Internet Security 2012 2012.0.2197
Avira Internet Security 2012 12.0.0.1127
ESET Smart Security 5 5.2.9.1
F-Secure Agent 1.57 Build 191, CUIF 10.01 build 32329, DAAS2 1.10 build 299
Kaspersky Internet Security 2012 12.0.0.374
McAfee Internet Security 11
Microsoft Security Essentials 4.0.1526.0
Norman Security Suite 9.00
Norton Internet Security 19.8.0.14
Panda Internet Security 2012 17.01.00
Total Defense Internet Security Suite 8.0.0.87
Trend Micro Titanium Maximum Security 6.0.1215


Download this unsponsored and independent report to see the full results.



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
bluelily
发表于 2012-11-3 12:45:56 | 显示全部楼层
应该是免杀测试     百分比越高越好
lsh90
发表于 2012-11-3 12:51:54 | 显示全部楼层
用bing翻译了下,方便 看

随着安全产品改进检测网络威胁的能力,以试图掩饰恶意软件按包装它与各种技术作出反应罪犯。这组测试报告分析的一些网络罪犯用来绕过或规避的消费者反恶意软件或端点保护产品 (EPP) 检测的常见方法。

网络罪犯做不只是开发一个攻击和移动上。相反,他们设法使他们的软件可用于尽可能长的时间。规避技术允许已知的威胁来规避安全产品的检测。

NSS 实验室测试 13 流行端点安全套件,以衡量其有效性在保护 Windows 计算机免受瞒。了解哪些产品的各种规避技术的覆盖率是产品质量的消费者需要了解的重要指标。消费者和企业实施了带自己的设备 (BYOD) 策略,寻求保护从桌面 Pc 和笔记本电脑的攻击的人应密切审查此测试的结果。

NSS 实验室 2012年利用保护比较分析报告已经表明大多数安全产品的能力,以检测范围广泛的利用漏洞攻击的弱点。逃避技术提供额外的手段,使攻击者能够向该终结点,提供同样的漏洞和增值产品传统上已经证明是穷人在处理这类技术。然而,此测试表明供应商已开始重视这种威胁,因为 anti-evasion 大大改善保护相比与先前的测试。

通过下面的测试用例的绝对数量排名显示图表。应该指出的是,产品可阻止执行,而不是下载,提供消费者比错过打包或压缩样本上执行的产品更好地保护。

此处为图片


主要调查结果
大多数供应商大大提高了其覆盖范围为我们而 NSS 实验室测试在 2010 年的测试中使用的基本瞒。
可执行的压缩机都为某些供应商仍然有问题。
大多数供应商不扫描的下载时,标准压缩机和一些不扫描上下载的压缩可执行有效载荷。
微软展示了最强的 anti-evasion 功能。
建议
修补有助于减轻影响的瞒、 自消费者应该始终保持他们的软件目前除了部署端点安全性。
使用不检查下载的压缩的软件的产品的消费者应联系其供应商,以协助其软件配置为扫描压缩的文件下载。
最新的浏览器可帮助阻止恶意的某些下载,并应使用较旧的浏览器支持。
测试的产品
Avast Pro 防病毒 7 7.0.1466
AVG 互联网安全 2012 2012.0.2197
Avira 互联网安全 2012 12.0.0.1127
ESET 智能安全 5 5.2.9.1
F-secure 代{过}{滤}理 1.57 生成 191、 CUIF 10.01 生成 32329、 DAAS2 1.10 建立 299
卡巴斯基互联网安全 2012 12.0.0.374
McAfee Internet 安全 11
Microsoft 安全要素 4.0.1526.0
诺曼安全套件 9.00
诺顿网络安全 19.8.0.14
熊猫互联网安全 2012 17.01.00
共防御互联网安全套件 8.0.0.87
趋势微钛最大安全 6.0.1215


下载此无人支持和独立的报告,以查看完整的结果。

评分

参与人数 1人气 +1 收起 理由
firefox3 + 1 版区有你更精彩: )

查看全部评分

哀酱俏佳人
发表于 2012-11-3 13:56:04 | 显示全部楼层
看来eset还不错
bbs2811125
发表于 2012-11-3 23:45:13 | 显示全部楼层
MSE不错嘛~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-7-17 23:19 , Processed in 0.131442 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表