123
返回列表 发新帖
楼主: The EQs
收起左侧

[分享] 这几天的战果

[复制链接]
The EQs
 楼主| 发表于 2007-3-10 18:05:38 | 显示全部楼层

回复 #20 风野胤 的帖子

偶去官方论坛问过了


Hi Guys,

Eset appreciates (a lot) all and every sample/s sent to its labs (samples@eset.com). Every sample is logged and examined using various methods. Addition of a sample-signature into the database is made on a need-to basis. Extraction of a signature of a sample is an automated process and could be completed in no time. However, Eset does not want to take part in a 'maximum-size-of-the-database' race and prefers to keep the database clean, i.e. without 'meaningless' benign signatures.

Some of the forum participants may recall the Rosenthal Utilities (RU) tests performed by CNET two years ago. All the 'simulated viruses' generated by the RU were benign (non-viral). 100% detection of the RU samples (achieved by some of the products) meant 100% False Alarm Rate. Detection of non-viral samples may lead to a couple of things: excellent results in some 'tests' combined with a false sense of security, a huge 'virus' signature database and 'dinosaur' update files.
Exponential increase of the number of new malware samples may often lead to a 'path-of-least-resistance' approach: automatic addition of all sample signatures, regardless of their viral nature.

Eset exchanges samples with several av vendors. Opposite statement is incorrect.

Speed of update and reaction time is of essence. Eset is fully aware of that. Advanced Heuristics has been developed and implemented with that in mind. The only acceptable reaction time is equal to zero. NOD32 achieves that often, e.g. it detected the infamous Netsky.A and Bagle.A heuristically.

Once again, I would like to thank you all: for both the samples and your patience :-)

anton
风野胤
发表于 2007-3-10 18:31:05 | 显示全部楼层
原帖由 EQ2 于 2007-3-10 18:05 发表
偶去官方论坛问过了


Hi Guys,

Eset appreciates (a lot) all and every sample/s sent to its labs (samples@eset.com). Every sample is logged and examined using various methods. Addition of a s ...

这解释很让人开心啊
eset果然是严谨的
The EQs
 楼主| 发表于 2007-3-10 18:37:01 | 显示全部楼层
哎。。。又得等待偶发送的样本了。。。。。
yzt1004
发表于 2007-3-10 18:52:14 | 显示全部楼层
印象中Eset以前说过他对待病毒样本有一个优先的问题,工程师会将大规模爆发的病毒设定高优先,先分析,至于低优先的什么时候排得到就难说了,一年都不一定。。。不知道现在是不是这样的。。。
EQ2有没有测试哪种方法得到回复最快?这个页面http://www.nod32-av.com/samples.htm效率怎么样?
The EQs
 楼主| 发表于 2007-3-10 18:54:55 | 显示全部楼层

回复 #24 yzt1004 的帖子

偶都是用邮箱+nod32自身的上报功能上报的。。。。很少用到网页上报。。。不过偶估计这个网页上报可能作用不大。。。因为如果是加密的话。。。。不知道他们会怎么分析。。。难道是暴力破解???
easy002008
头像被屏蔽
发表于 2007-3-11 08:20:39 | 显示全部楼层
原帖由 风野胤 于 2007-3-10 18:31 发表

这解释很让人开心啊
eset果然是严谨的


支持严谨,并不希望nod32把什么垃圾都往病毒库里堆
backupID
发表于 2007-3-11 10:15:57 | 显示全部楼层
楼组那么用心,何不当个版主玩玩,提升下nod32区的人气!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-19 15:12 , Processed in 0.104357 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表