查看: 7356|回复: 30
收起左侧

Kaspersky 今年六月没有通过 VB100 测试的官方声明

[复制链接]
KasperskyLab
发表于 2007-6-13 09:26:42 | 显示全部楼层 |阅读模式
VB failed - Official KL Statement

Kaspersky Anti-Virus 6.0 fails June VB test


As most people have probably heard, last month Kaspersky Anti-Virus 6.0.2.621 did not pass the test conducted by Virus Bulletin, the respected British publication on computer virology.
As stated in the Virus Bulletin report, this happened because Kaspersky Lab’s product did not detect one malicious program in the VB malware test set - Net-Worm.Win32.Allaple.e.

Extracts from the June edition of VB

In the June issue of Virus Bulletin John Hawes said that “detection (of this worm) was in place both a few days before and a few days after our test, and was presumably removed temporarily for some fixing. This unfortunate timing was enough to spoil Kaspersky’s recent solid record of VB100 awards”.

The quote above was taken from the following paragraph:
Reduced 75%
583 x 283 (43,89k)




What happened at Kaspersky Lab

The threat signature for Net-Worm.Win32.Allaple.e was added to the Kaspersky anti-virus signature databases on February 1, 2007, i.e. as soon as it emerged in the wild.

As part of Kaspersky Lab’s on-going efforts to improve efficiency and optimize overall performance, the threat signature for this worm was removed from the database - temporarily - for additional testing.

It is important to note, that user security was not compromised in any way due to our multi-faceted approach to security. The Proactive Defense Module, integrated into Kaspersky Anti-Virus 6.0 successfully detects and blocks this worm. As a result, user security is ensured by two complimentary technologies – anti-virus signatures and the PDM.

Unfortunately for Kaspersky Lab, the day that the signature was removed for testing coincided with the day Virus Bulletin was collecting anti-virus databases to conduct their tests. The databases downloaded for Kaspersky Anti-Virus 6.0 did not contain the signature for Net-Worm.Win32.Allaple.e. Since VB only tests signature-based detection, our product did not detect Net-Worm.Win32.Allaple.e.

The Kaspersky PDM

Kaspersky Lab’s Proactive Defense Module is able to block Net-Worm.Win32.Allaple.e and many other malicious programs even if a sample is not available in the threat signature databases.

The user receives a notification, identifying the threat, the potential danger and the history of the actions it has performed. After terminating the malicious program the user can rollback all changes, made by the malicious program in the system.

The screenshot below demonstrate how the Kaspersky Proactive Defense Module’s detects and blocks Net-Worm.Win32.Allaple.e.
Reduced 83%
874 x 496 (63,17k)




Conclusion

Of course, it is a great disappointment for us that a long series of successful Virus Bulletin tests -from August 2003 to May 2007 - has ended due to unfortunate timing.

But we are proud of the fact that our users’ security was not compromised even during the period when the signature was removed for maintenance – because our product’s proactive defense was able to block the malicious program 100%.

评分

参与人数 1经验 +2 收起 理由
wangjay1980 + 2 感谢发布

查看全部评分

KasperskyLab
 楼主| 发表于 2007-6-13 09:35:35 | 显示全部楼层
大致意思是说在测试那天,Kaspersky 的某个部门(机密)正在为优化软件性能,修改病毒库,送测的那天,Net-Worm.Win32.Allaple.e病毒可能被临时的移走了,所以没有查出来。VB测试组当时测的时候,是一项一项去测的,所以关闭了PDM(主动防御模块),也就没有查出来。

但是,就算这个病毒在那天没有加入病毒库存,正常用户只要打开PDM,依然能发现这个病毒,并且可以撤销这个病毒所进行的恶意操作。
sharkkong
头像被屏蔽
发表于 2007-6-13 09:59:20 | 显示全部楼层
用人不疑,疑人不用。这就是我对卡巴的态度
KasperskyLab
 楼主| 发表于 2007-6-13 10:01:25 | 显示全部楼层
不过我觉得这也是好事,健康的怀疑,虚心学习,都是促进技术进步的动力。
blog
发表于 2007-6-13 10:13:42 | 显示全部楼层
好像很多公司的商业稿都这样写的
今天又见一篇通用的解释稿。。。

理由谁都会找的
要想找理由,都可以找很多的
其它的公司也可以找一堆理由说自己为何没有通过,这有什么意思

没有通过就是没有通过,应该承认和反醒如何改进,这才是正道

卡巴应该反醒自己的傲慢,相关请看我的相关原创文章:http://bbs.kafan.cn/viewthread.php?tid=93306

[ 本帖最后由 blog 于 2007-6-13 10:16 编辑 ]
KasperskyLab
 楼主| 发表于 2007-6-13 10:27:43 | 显示全部楼层
原帖由 blog 于 2007-6-13 10:13 发表
好像很多公司的商业稿都这样写的
今天又见一篇通用的解释稿。。。

理由谁都会找的
要想找理由,都可以找很多的
其它的公司也可以找一堆理由说自己为何没有通过,这有什么意思

没有通过就是没有通过,应 ...


The question is - how hard will it impact KL's business?... That's not an easy to answer question - believe me.

[ 本帖最后由 KasperskyLab 于 2007-6-13 10:31 编辑 ]
鼠标右键
发表于 2007-6-13 10:32:39 | 显示全部楼层
原帖由 KasperskyLab 于 2007-6-13 10:27 发表
要考虑到VB100对市场采购的影响就明白了,如果让你去写,你也会这么写,但是私底下,的确需要思进取。

个人对vb100不了解  理解他们的解释  不过不知道咔吧有没有意识到要 自醒 进取 ....


对新闻不是很关注  谁能告诉我下 咔吧对那个时间bug 知道不知道?  官方是怎么解释的?>
谢谢
jlennon
头像被屏蔽
发表于 2007-6-13 10:35:30 | 显示全部楼层

回复 #5 blog 的帖子

同意你的观点,这让我想起了国足,草皮长了不好,短了也不好,气候适宜不好,下雨也不好。

西典的口号:木有任何借口
milk0548
发表于 2007-6-13 10:37:16 | 显示全部楼层
刚好凑巧而已,我还是相信卡巴的。一次没通过没关系,况且还不是技术上的原因。继续支持卡巴
suntaojohn
发表于 2007-6-13 12:40:28 | 显示全部楼层
还是支持卡巴。真没想到这么凑巧。当时病毒签名被取走分析去了,而正巧VB又在作测试,结果导致了出乎意料的结果。但是卡巴的主动防御还是可以100%阻止那个病毒入侵电脑的。相信卡巴
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-12-29 21:43 , Processed in 0.119278 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表