VirusInfo 2月份最新測試報告

2008-03-10 17:05:30 / 個人分類:addoption

How we test

The testing of anti-viruses by VirusInfo is powered by free online scanner VirusTotal. Project participants, being practising specialists in the area of computer security, are uploading at VirusTotal the malicious software that they have received form infected machines, and then publish the results of scanning in a special topic on VirusInfo forum. The malicious software should meet the following requirements:

1) The sample should not be detected by the anti-virus software that protects the infected machine.

2) The sample should be found by the consultant him/herself in a real infection case.

3) The sample should not be taken from some other site or from some other collection of malware.


The results of scanning are regularly generalized as a graph of detection level. The graph is prepared in accord with the following principles:

1) The X axis represents the anti-virus software used by VirusTotal at the current moment. The Y axis represents the number of samples uploaded.

2) For each antivirus we mark the number of samples that it has successfully detected using one or another detection method. The graph reflects the general number of detected samples and the each method's part in the general detection.

3) The following detection methods are distinguished:

a) signature detection (detecting already known malware by the signature method)

b) heuristic detection (detecting yet unknown malware by the method of emulation / code analysis / etc. Examples: "Heur.Trojan.Generic"; "a variant of: XXXXX")

c) detection of suspicious file (detecting yet unknown malware by the method of informing the user about suspicious characteristics of a sample under analysis. Examples: "Suspicious file"; "VIPRE: Suspicious")

d) detection of suspicious cryptor / packer (detecting yet unknown malware by the method of informing the user about the unknown / rare / suspicious packer / cryptor or about the fact of multiple packing / crypting. Example: "HEUR/Crypted").

Testing results

The latest one is the graph for February, 2008, presented below.



General conclusion

In February, 2008 the leader of the testing is Webwasher-Gateway due to its combination of signature, heuristic and packer / cryptor detection methods. The second and third places belong to F-Secure for its good signature detection combined with heuristic module and AntiVir - by the very same reasons as the leader. The worst product in February was FileAdvisor.

The best percent of each method in the whole detection rate: signature method - F-Secure; heuristics - Prevx1; suspicious - eSafe and Panda, packers / cryptors - AntiVir and WebWasher-Gateway.

Comments on how we test and how to understand the results

The material for testing is collected irregularly and voluntarily. VirusInfo publishes a new graph each month. The testing cannot be regarded as the one which completely reflects the detection abilities of anti-virus software, at the same time the data received are of certain value when comparing antiviruses in a complex way, taking into consideration the results of several independent tests.

Additional info

Materials for testing are collected in the Russian section Antiviruses, anti-Spyware/Adware/Hijackers of VirusInfo forum. In that section the forum members can access the earlier graphs. You may discuss the results of testing in English here.

Licensing

Copyright (c) VirusInfo.
All rights reserved.
Using the materials of this article without mentioning the source is prohibited.

Statistics is collected and processed by Shu_b
» Testing: Previous month

TAG: addoption

integear發佈於2008-03-12 22:37:16

QUOTE:

原帖由 walkingfish 於 2008-3-10 20:40 發表
瑞星是為了要收集病毒而加入 VirusTotal ?
加入的廠商都是 .
integear發佈於2008-03-12 22:36:52

QUOTE:

原帖由 iorittn 於 2008-3-10 18:55 發表
suspicious是指報可疑可是沒正確抓到的嗎?
pack/crypt這個是什麼?

卡巴居然輸給F-secure很長一根.....
F-secure多引擎果然強
Suspicious是"可疑的",與Heuristics(啟發式)最大的不同是:Suspicious主要以報殼(加多重殼,特定殼)為準 .

Heuristics則以防毒廠商自行訂定之規則或威脅資料庫比對所判斷而成,但是這部分很難區分,因為有的廠商濫用Heuristics為啟發,但實則為報殼 .

Pack/Crypt是指"報殼",常見的是AntiVir報TR/Crypt.XXX .
walkingfish發佈於2008-03-10 20:40:10
瑞星是為了要收集病毒而加入 VirusTotal ?
iorittn發佈於2008-03-10 18:55:00
suspicious是指報可疑可是沒正確抓到的嗎?
pack/crypt這個是什麼?

卡巴居然輸給F-secure很長一根.....
F-secure多引擎果然強
天氣預報發佈於2008-03-10 18:40:55
其實通常會丟VT的都是自己防毒軟體掃不到的
所以越多人用的
在這測試表現都會不如預期
我還是等AV-C的吧
andy的個人空間 andy 發佈於2008-03-10 17:41:50

QUOTE:

原帖由 000110 於 2008-3-10 17:38 發表
卡巴最近給人的感覺總是怪怪的
可能投放資源在新版上
大大要多努力為mcafee上報


F-secure 有自家的啟發引擎, 好像是gemmi
不過看它報的次數不多
主要有作用的是 AVP和Norman, 其他的引擎出現次數少之有少

搞不懂....
000110的個人空間 000110 發佈於2008-03-10 17:38:32
回復 3# 及 4# 的帖子
卡巴最近給人的感覺總是怪怪的
可能投放資源在新版上
大大要多努力為mcafee上報


F-secure 有自家的啟發引擎, 好像是gemmi
不過看它報的次數不多
andy的個人空間 andy 發佈於2008-03-10 17:29:04

QUOTE:

原帖由 000110 於 2008-3-10 17:12 發表
F-Secure 的偵測率的升幅很大
不論在已知還是未知的偵測
偵測率更超越卡巴
VT 上的 FS, Norman 引擎 也可以用來掃瞄吧,內部版就是強 , AVP+Norman
結果看出是 AVP和Norman 重覆不多 ,啟發比Norman 還要長

反之,就是他們計算上出錯

總是覺得怪怪的

[ 本帖最後由 andy 於 2008-3-10 17:30 編輯 ]
a750828發佈於2008-03-10 17:28:43
這個月的卡巴的確有點虛的感覺,不過為什麼2月的McAfee完全沒有啟發式偵測???
000110的個人空間 000110 發佈於2008-03-10 17:12:51
F-Secure 的偵測率的升幅很大
不論在已知還是未知的偵測
偵測率更超越卡巴
我來說兩句

(可選)

Open Toolbar