楼主: The EQs
收起左侧

[讨论] 大概分析了一下nod32之所以支持vb和av-c的原因分析

[复制链接]
The EQs
 楼主| 发表于 2007-3-5 02:15:48 | 显示全部楼层

回复 #30 solcroft 的帖子

你没看到nod32官方论坛的帖子???wildlist说它权威是因为有很多反病毒分析师参与到其中。。。而且里面的病毒都是真实的。。有效的。。你还是没看明白vb是怎么判断一个杀软通过与否的。。。另外偶今天这里网速不是很好。。。so得打快一点字。。。。有很多就一带而过。。。偶也说了。。。而且金山也不是查杀所有的病毒。。。建议你自己去wildlist的主页看看到底有多少病毒。。。vb测试的itw的确是800个。。。
The EQs
 楼主| 发表于 2007-3-5 02:17:31 | 显示全部楼层
如果金山能查杀从1993年到06年wildlist所有的病毒的查杀效率在90%以上那才叫做强。。。可以全球没有几个厂商能查出来。。。eset也不可能达到100%
solcroft
发表于 2007-3-5 02:34:01 | 显示全部楼层
VB100 test procedures        A VB100 award denotes that the product in question showed, in its default        mode, 100 per cent detection of In the Wild        test samples         and no false positives in a selection of clean files.       


http://www.virusbtn.com/vb100/about/100procedure.xml

别把自己当专家来献丑了,自己先去搞清楚吧

把病毒名字贴出来,除了显出ItW病毒就的确那么少,其他的也证明不了什么。
要把用这么几个病毒来测试杀软的评测说成“世界权威”,贻笑大方也。

瑞星达到84.78%查杀率,阁下说成搞笑评测,金山达到了99.78%查杀率,阁下却拼命找借口... 脸皮的厚度倒是世界权威了
最后再送你一句劝告
不要以为自己是什么“正义战士”,为VB100%“打抱不平”了
不懂得看事实说话的人,顶多也只是个小丑罢了。
The EQs
 楼主| 发表于 2007-3-5 02:37:06 | 显示全部楼层
原帖由 solcroft 于 2007-3-5 02:34 发表


http://www.virusbtn.com/vb100/about/100procedure.xml

别把自己当专家来献丑了,自己先去搞清楚吧

把病毒名字贴出来,除了显出ItW病毒就的确那么少,其他的也证明不了什么。
要把用这么几个病毒来 ...

http://www.virusbtn.com/old/comparatives/Vista/2007/test_sets.html
The EQs
 楼主| 发表于 2007-3-5 02:38:37 | 显示全部楼层
我不知道你有没有完全看完



VB100 test procedures
A VB100 award denotes that the product in question showed, in its default mode, 100 per cent detection of In the Wild test samples and no false positives in a selection of clean files.

For on-demand scanning of files, detection is considered to be a note in the product log file that the file is infected or very likely so. For on-demand scanning of boot sector viruses, a notification or log file entry is required.

For on-access scanning the matter is a little more confusing, since the best method of testing - executing all files and using the results from this activity - is clearly impractical. Detection is thus judged by a product denying access to an infected file when the file is opened for writing.

For boot sector on-access scanning a visible notification or log file entry is required. In this case denial of access is not a useful guide to detection since the VB boot sector test floppies are all blank as far as file contents are concerned. Since denial of access is likely to show a blank disk as the only detectable effect, this is not particularly useful. The addition of extra files to the disk for use in deciding whether access has been denied was decided against, for in past testing some products were only able to detect a boot sector virus on a floppy containing other files - a situation which would be apparent only with the use of disks in their current state.

Products which cannot be cajoled into producing reasonable logs on demand are checked by setting the product to delete and/or disinfect. The files are then scanned until no more detections are present, if necessary manually noting those files which are detected as infected but are not deleted or disinfected. Disinfected files are removed from the test set by use of CRC checking, and those files left in the test set are considered to be misses.

Near misses
There remains ample opportunity for products to miss detection, in our tests, of files which they are perfectly able to detect - why? Of the many potential answers, two are most likely. First, there are the matters of default extension lists, a common area for failure over the years, in which products have failed to gain VB100 awards because the default extension lists did not include possible extensions for In the Wild viruses. In most cases these extension-based problems are easily solved by an administrator adding extensions to the default list. We could perform these changes prior to testing. We feel, however, that our readers are better served if they know that they have to do this, than if we scan all files regardless of extension.

Another example of why some products miss out on VB100 awards, is where certain files are not scanned directly on-access. The usual assumption by the product developers is that the files will be scanned when passed on to an application which makes use of them. At the most common level this covers such objects as ZIP files, which are often not scanned until unzipped and EML files, which are not scanned until individual mails are pulled from within. From a developer's point of view these choices make sense in that leaving objects unscanned until use creates fewer overheads. The chance of infection on a protected machine is not increased, since scanning will occur before code execution. Such treatment of objects does, however lead to misses under the VB100 testing methodology.

Three chances
Each product may be tested up to three times on two different test machines. Should any product fail to work after three attempts the testing process will be aborted for that product.

VB100 award
A VB100 award means that a product has passed our tests, no more and no less. The failure to attain a VB100 award is not a declaration that a product cannot provide adequate protection in the real world if administered by a professional. We would urge any potential customer, when looking at the VB100 record of any software, not simply to consider passes and fails, but to read the small print in the reviews.
The EQs
 楼主| 发表于 2007-3-5 02:40:47 | 显示全部楼层
偶不知道你是这么认为wildlist的。。。。。你如果仔细去wildlist官网看看就知道一切了。。。wildlist并不止ITW这个清单。。。。
solcroft
发表于 2007-3-5 02:42:05 | 显示全部楼层
我只把重要的部引用出来,要通过VB100%只需查全ItW样本和零误报即可,其他方面表现多差都无所谓。
不知阁下贴了一大片文章想说明的是什么?

没空和你胡扯了,竟然连WildList都看不懂,要我去看的目的不会是要我来向你解释吧
连ItW List和Supplemental List的差别也分不清
连VB100%测试不使用Supplemental List样本这个简单道理你到现在还搞不懂
明天早上还得和秃头教授搞上一场,我先去睡了,你就慢慢继续胡说吧。

[ 本帖最后由 solcroft 于 2007-3-5 02:46 编辑 ]
The EQs
 楼主| 发表于 2007-3-5 02:43:38 | 显示全部楼层

回复 #37 solcroft 的帖子

你所说的wildlist里面就只认为有itw??wildlist有主要清单和补充清单之分。。另外你还没搞懂vb到底是怎么评测的。。。。
The EQs
 楼主| 发表于 2007-3-5 02:45:56 | 显示全部楼层
这里指的wildlist你就单纯的认为是itw???
The EQs
 楼主| 发表于 2007-3-5 02:46:35 | 显示全部楼层

回复 #37 solcroft 的帖子

不知道谁在胡说。。。wildlist分主要清单和补充清单。。。
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 09:03 , Processed in 0.089412 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表