#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity
|
|
Rather an unusual meeting was held just a few days ago in Iceland. Major AV developers and AV testers met for two days and discussed many important aspects of how contemporary products should and should not be tested.
The workshop was held on 15-16 May and there were 66 attendees representing many computer security companies (AhnLabs, Aladdin, Alwil, Authentium, Avira, Bit9, Datsec, Earthlink, EMSI, Eset, Frisk, F-Secure, Gdata, Grisoft, K7, Kaspersky, McAfee, Message Labs, Microsoft, Norman, Panda, Softwin, Sophos, Symantec, Trend, UMU) and major testing bodies (K.Brunnstein of Virus Test Center in Hamburg University, A.Clementi of av-comparatives.org, J.Hawes of Virus Bulletin, A.Marx of av-test.org and M.Parsons of Westcoast Labs).
The attendees, of course, knew each other very well even before the meeting. After all we do regularly get together at major conferences devoted to malware research. But never before have we had a chance to focus our discussions of security products’ testing and do it in such a depth.
Let me highlight the following points in our discussions:
- how to test and compare security products that provide different and multiple lines of defense (for example – pure scanner versus behavioural/heuristic system or a system with protection rules; with or without firewall, etc.)
- focus on prevention and positive user experience
- total live virus testing (real sample running on a real computer – not only an on-demand scan of a file collection)
- detecting programs that are packaged using “bad” packers/protectors (they are frequently used to obfuscate programs and many of them are almost exclusively used by the bad guys to hide and mutate viruses, trojans and adware)
- discussions about the Wildlist and how the “telemetry” data collected by AV companies can improve the information about threats in the field
- discussions about government-approved backdoors and surrounding laws should they appear (also known as “Magic Lantern” and “Bundestrojan” problems)
- test strategies and common mistakes
- testing heuristic detections
I found the meeting very useful and I am very glad to use this opportunity to thank all the employees of Frisk Software who organized the workshop!
|
|
Submit your own comments / message for this post