查看: 3290|回复: 11
收起左侧

转载-看nod32官方对病毒库态度之严谨

[复制链接]
easy002008
头像被屏蔽
发表于 2007-3-14 11:55:19 | 显示全部楼层 |阅读模式
Hi Guys,

Eset appreciates (a lot) all and every sample/s sent to its labs (samples@eset.com). Every sample is logged and examined using various methods. Addition of a sample-signature into the database is made on a need-to basis. Extraction of a signature of a sample is an automated process and could be completed in no time. However, Eset does not want to take part in a 'maximum-size-of-the-database' race and prefers to keep the database clean, i.e. without 'meaningless' benign signatures.

Some of the forum participants may recall the Rosenthal Utilities (RU) tests performed by CNET two years ago. All the 'simulated viruses' generated by the RU were benign (non-viral). 100% detection of the RU samples (achieved by some of the products) meant 100% False Alarm Rate. Detection of non-viral samples may lead to a couple of things: excellent results in some 'tests' combined with a false sense of security, a huge 'virus' signature database and 'dinosaur' update files.
Exponential increase of the number of new malware samples may often lead to a 'path-of-least-resistance' approach: automatic addition of all sample signatures, regardless of their viral nature.

Eset exchanges samples with several av vendors. Opposite statement is incorrect.

Speed of update and reaction time is of essence. Eset is fully aware of that. Advanced Heuristics has been developed and implemented with that in mind. The only acceptable reaction time is equal to zero. NOD32 achieves that often, e.g. it detected the infamous Netsky.A and Bagle.A heuristically.

Once again, I would like to thank you all: for both the samples and your patience :-)

anton





eset感谢用户上报给实验室的病毒,每一个病毒都记录在案并采用不同的方法进行分析.将病毒签名添加到数据库的过程是按照实际需求来做的,提取病毒签名是自动过程可在瞬间完成.但是eset无意参加最大病毒库的角逐,而是尽量保持病毒库的纯净,也就是说,不包含没有意义的无害签名.



一些论坛成员或许还记得CNET前两年做的RU测试,当时RU模拟的所有病毒都是无害的,不具备病毒特性.因此在RU测试结果中,100%查杀就意味着100%误报.检出无害样本会导致在虚假安全表像的测试中取得优异的结果,病毒签名数据库庞大,以及恐龙般大小的升级文件.

新恶意软件样本的成倍增长,常常会使杀软开发商走避重就轻的捷径:自动添加所有样本签名,而无视其病毒特性.



eset与数家杀软开发商之间交换病毒样本,任何反面的说法都是不正确的.



升级速度和反映时间是至关重要的,eset深知这一点,高级启发式判断技术就是由此开发和实施的.可以接受的反映时间几乎是零,nod32常常做到这一点,比如启发式技术同步检测出臭名昭著的Netsky.A和Bagle.A病毒.



对大家所提交的病毒和各位的耐心,表示再次感谢!


anton
eset官方论坛版主


由此可见nod32之严谨!
windlau78
头像被屏蔽
发表于 2007-3-14 12:00:44 | 显示全部楼层
可以看出NOD32拥有自身的原则。
wangzoom
发表于 2007-3-14 12:27:27 | 显示全部楼层
是啊,杀软的好坏不光要看病毒库,自身的特色不能丢啊
xiaoz
发表于 2007-3-14 12:57:48 | 显示全部楼层
就是就是,用NOD的人都知道这点的。
solcroft
发表于 2007-3-14 13:08:30 | 显示全部楼层
那个帖子快要四年前的事了
ESET就是想说说这么几句话把用户打发掉
直到今天处理样本速度还是那么慢
用过虚拟机+Cyberhawk测试的有效病毒上报了还是那么一副爱理不理的态度
The EQs
发表于 2007-3-14 13:20:46 | 显示全部楼层

回复 #5 solcroft 的帖子

malware是慢了点。。。木马倒是很快。。。
ktango
发表于 2007-3-14 13:21:14 | 显示全部楼层
NOD32是不錯的防毒。
wmh2008
发表于 2007-3-15 22:23:57 | 显示全部楼层
希望一直保持这个原则~~
wpbisyman
发表于 2007-3-15 23:00:25 | 显示全部楼层
特色就是启发
adonis219
发表于 2007-3-16 06:48:44 | 显示全部楼层
正想用用~~~~~~~~~~
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-2 23:22 , Processed in 0.145394 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表