AV-Test (2008/9/2) 百萬樣本正式測試

字體: | 打印

AV-Test release latest results
Major test of suite products completed
Independent testing body AV-Test.org has released the results of a major comparative of suite products, with many vendors' 2009 editions included in the results. The test covers a range of metrics, including detection rates over various types of malware including adware and spyware, false positive rates, scanning speed, proactive detection, and response times to outbreaks.
In terms of pure detection rates in on-demand scanning,
a beta version of GDATA's AVK 2009 topped the charts for both 'malware' (measured against 1,164,662 samples) and 'ad- and spyware' (94,291 samples), with Avira's Premium Security Suite 2008 a close runner-up in the former category and F-Secure 2009 placing second in the latter. Secure Computing's Webwasher gateway product, based on the Avira engine with some in-house heuristics, came third in both categories.
Other areas analysed were scored on a five-point scale from very good to very poor. 'Proactive' protection included scanning of files discovered after the freezing of products, and executing unrecognised malware to test behavioural protection. Products rating 'good' or better in every category include Avira's premium suite (the popular free version has less complete spyware detection), AVK 2009, F-Secure's 2009 suite, Symantec's Norton I.S. 2009 (still in beta) and Sophos's Security Suite 2.5. All products taking part in the test managed to achieve a 'good' or better in at least one category.
The test also included keeping a record of the number of updates released over a four-week period. Of course, these numbers on their own cannot be used to measure the quality of the products involved, but were recorded out of interest. The most interesting data to emerge from this measurement was that the 2009 version of Norton topped the table with an impressive 6,202 incremental micro-updates, issued several times per hour, while Kaspersky came a distant second with a mere 696. Half of the 34 products tested had fewer than 100, including those from McAfee (21) and Trend Micro (30).
A summary of the major areas tested is printed below; hover over the product names to see full version information.        
Productmalware on demandadware / spyware on demandfalse positivesscan speedproactive detectionresponse timesmalware on demandadware / spyware on demand
AntiVir (Avira)++++ (4)++++++99.8%99.0%
Avast! (Alwil)++++++oo99.3%98.3%
AVG+- (4)++oo95.8%87.0%
AVK 2008 (G Data) (1)++++o-+++99.2%99.1%
AVK 2009 (G Data) (2)++++++++++99.8%99.8%
BitDefender 2008+-+-+++97.7%87.8%
BitDefender 2009+-+o+++97.6%88.0%
CA-AV (VET)----++o---65.5%68.0%
ClamAV-o----++88.5%92.8%
Dr Web---oo+o84.9%89.6%
eScan++o-+++97.8%97.4%
Fortinet-GWo--o++++92.6%81.9%
F-Prot (Frisk)oo++oo94.8%92.6%
F-Secure 2008+++++o+++98.2%98.4%
F-Secure 2009++++++++++99.2%99.6%
Ikarus++++o+++99.5%98.6%
K7 Computingooo++-o92.1%94.0%
Kaspersky++++oo+++98.4%98.3%
McAfeeoo++o+-93.6%94.5%
Microsoft++++o--97.7%97.1%
Nod32 (Eset)oo+++++++94.4%94.7%
Norman+++o+o96.3%95.8%
Norton 2008 (Symantec)+o++++o97.8%94.6%
Norton 2009 (Symantec)++++++++++98.7%95.4%
Panda 2008-o++++o86.4%93.4%
Panda 2009o++++++91.8%95.6%
Rising----+ooo83.4%77.5%
Sophos+++++++97.5%95.0%
Trend Microo-++o+91.3%88.5%
TrustPort++++---++++99.5%98.4%
VBA32o-oo+o90.5%85.2%
VirusBuster--++oo89.0%85.8%
WebWasher (3)++++o++++++99.7%99.2%
ZoneAlarm++oo+++97.8%97.7%
Indexmalware on demandadware / spyware on demandfalse positivesscan speedproactive detectionresponse timesmalware on demandadware / spyware on demand
++>98%>98%no FP

< 2 h

+>95%>95%1-2 FP

2 - 4 h

o>90%>90%3-4 FP

4 - 6 h

->85%>85%5-6 FP

6 - 8 h

--<85%<85%> 6 FP

> 8 h

Notes
(1) AVK 2008 uses the Avast and Kaspersky scan engines
(2) AVK 2009 uses the Avast and BitDefender scan engines
(3) WebWasher uses the Avira engine and a self-developed heuristic engine
(4) the free (personal) edition does not include ad- and spyware detection, so the results would be --
02 September 2008

我也來說兩句 查看全部評論 相關評論

  • 天氣預報 (2008-9-04 01:30:32)

    NIS 2009贏過卡巴斯基?
    NIS 2009目前那個病毒定義檔還不是很完全耶
  • ㄚ一 (2008-9-04 01:44:42)

    Panda大小眼?
    Response Time居然08跟09會不一樣?!
  • ㄚ一 (2008-9-04 01:47:55)

    Kaspersky目前也在重整特徵庫
    預計要三個月左右才會恢復以往的水準
  • 天氣預報 (2008-9-04 01:49:09)

    好幾家的response times前後兩版都不一樣
    是有新技術?
  • ㄚ一 (2008-9-04 02:04:05)

    剛剛發現BitDefender也是..
    不曉得這個Response Time是怎麼個測法?
  • 天氣預報 (2008-9-04 02:11:55)

    15號的AV-C依照慣例很有可能測KIS 2009和NIS 2009
  • Bug (2008-9-04 02:16:31)

    第一段的最後一句 : response times to outbreaks

    病毒爆發的反應時間

    是不是依照發現"同一個新病毒"的偵測反應時間來做統計排行

    那新舊差異是在於...

    啟發?

    [ 本帖最後由 Bug 於 2008-9-4 02:23 編輯 ]
  • Bug (2008-9-04 02:19:04)

    請參考 :

    http://www.kaspersky.com.tw/KL-A ... _to_New_Threats.htm

    [ 本帖最後由 Bug 於 2008-9-4 02:20 編輯 ]
  • 郭政勳 (2008-9-04 02:25:22)

    F-secure 2009 發威了
  • ㄚ一 (2008-9-04 02:33:33)

    可以給我這篇測試的來源嗎?
    我想直接去問人
  • 天氣預報 (2008-9-04 02:42:04)

    Norton最近反應速度有進步不少
    (自動化的部分)
  • Bug (2008-9-04 02:48:08)

    已PM
  • abletw (2008-9-04 08:15:58)

    Kaspersky依然是誤報大王...

    Sophos跟Trendmicro連Microsoft都不如,好玩!

    Panda果然更爛!!!依然要被時代潮流給淹沒

    Nod32也該被淘汰了,如果還不長進點的話…

    McAfee可能真的得去賣咖啡了

    看好微軟的後勢...

    這篇來源不就是http://www.virusbtn.com/news/2008/09_02

    [ 本帖最後由 abletw 於 2008-9-4 08:18 編輯 ]
  • ㄚ一 (2008-9-04 13:04:52)

    Kaspersky從來都不是誤報王
    像你這樣看一篇測試說一種話的人才好玩...
  • shenhwang (2008-9-04 16:36:13)

    分享一下我的看法,單純個人意見
    1.某個知名電腦雜誌評論某款產品不好,造成該廠商被代理商退貨,進而導致關門大吉
    2.類似的產品在狗仔周刊包裝行銷下,產品大熱賣,廠商賺大錢
    產品沒有好或壞,只有能否滿足使用者的需求
    不能符合我需求的產品,搞不好符合其他人的需求
    而每個人的需求是絕對主觀的

    希望AVPClub是像狗仔周刊一樣,推薦好的產品,讓消費者和廠商雙贏
    而非只是主觀、漫罵,造成網站、使用者、廠商都輸

    各式各樣的測試報告,當做參考就好
    這次的KL誤報是0,也有其他家誤報是--,也許下次都是++

    有些樣本是由機器自動分析,難免會被誤報,但只要回報newvirus,很快就會解除
    測試只是當下,但產品和服務是要做長久的,口碑也是這樣慢慢建立起來

    KL最近在整理資料庫和樣本分析機制
    更新周期會拉的比較長,希望陣痛期很快就能過去

    期待Kaspersky Security Network發揮功效
  • sun88990 (2008-9-04 17:07:26)

    QUOTE:

    原帖由 郭政勳 於 2008-9-4 02:25 發表
    F-secure 2009 發威了
    恩..最近也有發現到~
    卡巴不能偵測的有些FS可以靠啟發偵測~~
    --
    McAfee的那一欄我覺得也很怪~
    McAfee的掃描速度很快阿~比Avira,ESET慢一些而已!(詳情請去看AV-C測試)
    新的5300引擎我覺得比AV-C上次測的5200引擎快很多了~

    [ 本帖最後由 sun88990 於 2008-9-4 17:10 編輯 ]
  • 黑衣~魂 (2008-9-04 17:09:37)

    這個測試再加上Bug提供的反應資料,其實可以得到一個結論,其實有在95%以上的軟體都有一定的偵查率,各家的偵查率越高越接近,就已經變成在考驗各家廠商的labs反應時間而已!如果廠商沒有辦法提供即時迅速的分析處理反應方式,偵查率再高有都沒有意義的!因為新的sample一直會有,新的malware會不斷出現而不是永遠只侷限在這區區一百萬樣本而已!

    labs反應時間其實最近我也小測一些廠商,我發現有越來越多的廠商已經變得不在乎反應速度與回信跟客戶的橋樑斷的差不多了,這種廠商出的軟體實在沒有購買的意義,當然還是有廠商把持住這種服務信念

    反應這一點我認為kaspersky幾乎在6小時內可以回信,microsoft也做起來在6~24小時內,Avira,F-Secure他們的表現都很不錯

    反觀那些號稱領導大廠做不起來就實在太可笑,還有藉口說成千上萬的樣本所以....怎樣,也只是拿石頭砸自己的腳!

    [ 本帖最後由 黑衣~魂 於 2008-9-4 17:11 編輯 ]
  • sun88990 (2008-9-04 17:14:06)

    QUOTE:

    原帖由 黑衣~魂 於 2008-9-4 17:09 發表
    這個測試再加上Bug提供的反應資料,其實可以得到一個結論,其實有在95%以上的軟體都有一定的偵查率,各家的偵查率越高越接近,就已經變成在考驗各家廠商的labs反應時間而已!如果廠商沒有辦法提供即時迅速的分析處理反應 ...
    微軟沒這麼慢喔~它是用智能分析的~
  • sun88990 (2008-9-04 17:18:16)

    QUOTE:

    原帖由 黑衣~魂 於 2008-9-4 17:09 發表
    labs反應時間其實最近我也小測一些廠商,我發現有越來越多的廠商已經變得不在乎反應速度與回信跟客戶的橋樑斷的差不多了,這種廠商出的軟體實在沒有購買的意義,當然還是有廠商把持住這種服務信念
    我之前也有測試過~
    可是Avast,McAfee,CAT-QuickHeal,安博士
    這些小商嗎?
    而且F-PORT的上報網站好像也掛了~ 去測試看看吧!!
  • integear (2008-9-04 18:04:02)

    VB100%也已經公布測試報告了,可參考:http://www.virusbtn.com/news/2008/09_02

    比較值得注意的:AntiVir免費版由於沒有提供間諜資料庫,所以免費版的成績會是"--",就是85%以下 .