查看: 2036|回复: 3
收起左侧

[资讯] Security analysts closer to improved antivirus software test

[复制链接]
The EQs
发表于 2007-10-10 13:17:28 | 显示全部楼层 |阅读模式
San Francisco (IDGNS) - Antivirus vendors are closer to agreeing on a new way to test their software after widespread agreement that older antivirus tests can be misleading. AV-Test.org, a German antivirus testing organization, is meshing suggestions from vendors such as Symantec, Panda Software, and Trend Micro as well as its own for a new testing regime, said Maik Morgenstern, who conducts product tests at AV-Test.org. The new testing proposal -- also supported by vendors Kaspersky Lab and F-Secure, as well as other testers such as Virus Bulletin -- will be presented next month at the Association of AntiVirus Asia Researchers 2007 conference in Seoul. Companies supporting AV-Test.org's paper will try to marshal support from other security vendors, said Mark Kennedy, an antivirus engineer with Symantec. "We believe this is the way tests should be conducted," Kennedy said. "The hope is that other companies will join us." Still, the proposals will be optional guidelines for antivirus testers, which ultimately can choose to adopt or ignore them. Antivirus testing groups have typically tested antivirus products by running the detection engine against hundreds of malicious software samples. If the product doesn't detect a sample, it gets a lower ranking. The style of evaluation tests whether an antivirus product has the right "signatures," or indicators that can identify a specific piece of malware. The test is relatively quick and easy to perform. But over the last three years or so, many security companies have added technology that can flag malware based on how it acts. That's because signatures have become a less reliable way to defend a computer due to the high number of malware variations that now appear on the Internet. A signature test does not take into account behavioral detection technology, so vendors have argued that a failed signature test doesn't mean their product wouldn't have protected a PC. Software vendors have proposed testing antivirus products under the same conditions a consumer would encounter on the Internet. In essence, antivirus testers would use real, active malicious software samples from the Internet and present them to computers in the same way people encounter them, such as through e-mail attachments or Web pages rigged to exploit browser vulnerabilites. Before a test, antivirus suites would be "frozen" a few weeks prior and not allowed to update their signatures in order to really test the proactive or behavioral technology. Debate is still ongoing whether testers should use malware that is actually doing bad things on the Internet, which poses questions of whether the test machines could potentially do harm. An alternative is setting up a simulated Internet environment in the lab, but that may not allow malware to run in the way it would if it could access the Internet. "There's always a trade-off," Morgenstern said. Security analysts are still working on how the products will be scored. It's tricky, since there are many different levels at which a product may detect and neutralize a threat. The scoring has to be clear and comprehensible to people who read technology magazines that write about the tests. "If the magazines are not able to communicate that in a simple manner to the consumer, then it's not worth much," said Pedro Bustamante, senior research advisor for Panda. The new parameters mean it will likely take a lot longer to conduct the tests, but Morgenstern said he believed AV-Test.org could do it with their existing staff and without any significant fee increases to publishers who commission work from them.
taihuxian
发表于 2007-10-10 13:21:46 | 显示全部楼层

关键是以下这句,原来是要测试主动防御和启发了

In essence, antivirus testers would use real, active malicious software samples from the Internet and present them to computers in the same way people encounter them, such as through e-mail attachments or Web pages rigged to exploit browser vulnerabilites. Before a test, antivirus suites would be "frozen" a few weeks prior and not allowed to update their signatures in order to really test the proactive or behavioral technology
实质上,反病毒测试将使用来自网络的真实的,活体病毒样本,将他们以用户遭遇相同的方式植入电脑,比如通过电子邮件附件,利用浏览器漏洞的网页等。在测试前,反病毒软件需要被“冻结“几周,不允许升级病毒库,目的就是为了测试主动防御和行为启发技术。

[ 本帖最后由 taihuxian 于 2007-10-10 13:27 编辑 ]
xffsfy
发表于 2007-10-10 18:03:04 | 显示全部楼层
不知道他们用不用QQ,知不知道传奇外挂...
傻猪猪米走鸡
发表于 2007-10-10 18:05:05 | 显示全部楼层
其实很多人都只是个qq被盗就再来一个的人……
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-11 16:53 , Processed in 0.121129 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表