About Me

Hiep Dang

Hiep Dang
Hiep Dang is the director of operations for McAfee Labs. He is currently in charge of opening a new research & ...

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Many Facets of AV Testing

Friday, January 25, 2008 at 2:00pm by Hiep Dang
Hiep Dang

Following the news from my colleague Dr. Igor Muttik about his recent trip to Bilbao, Spain, to participate in the Anti-Virus Testing Workshop, AV-Test.org just released the results of their latest comparative test. It was picked up by many media outlets:

  1. PC Magazine (USA)
  2. Dark Reading (USA)
  3. PC Welt (Germany)
  4. CHIP (Germany)
  5. Security.nl (The Netherlands)

Unlike in many previous reviews, AV-Test.org ran various types of tests, and McAfee scored well in most of them:

Test Type
Rating
Signature-based
Good
More than 90% detection rate out of 1 million files
Proactive
Good

False-positive
Very Good
No false-positives detected out of 65,000 clean samples
Rootkits
Good
Detected all running rootkits except one
Response times
Poor
Around 6 to 8 hours
  • We are pleased that we made the most progress of any vendor from AV-Test.org’s last test, which was published by c’t magazine (Germany) earlier this month. Our detection-rate improvement was +7.3%.
  • We are proud that we did not detect any false positives. (We are one of only three vendors that can make that claim.)
  • We received the second-best rating in the Rootkits test.

Signature-Based Tests are usually an on-demand scan (ODS) by anti-malware products on a computer system against a set of known malware. We have discussed the challenges in making this test fair in the past.

Proactive Tests are similar to signature-based tests, except that they attempt to measure how well an anti-malware product can detect samples that it has never seen before–by taking an old DAT version and scanning with malware that was discovered after the DAT release date. This test often gives a sense of how well an anti-malware vendor does in writing generic, heuristic, or behavioral signatures. The caveat with this is that if a product ventures too far into this realm, the likelihood of false-positives increases.

False-Positive Tests are also an ODS test, except with a sample set of clean files instead of malicious files. False positives are the bane of the anti-malware industry as they could have far worst collateral damage than a false-negative (missed detection) depending on the severity. Because of our large customer base, we take this metric very seriously and have an internal zero-tolerance policy.

Rootkits Tests are one of the most complex and time-consuming tests that a tester can run, and are similar to the behavioral tests described above. However, these require even more intimate knowledge of both the target operating system and known rootkit techniques to accurately judge whether an anti-malware product was able to properly remediate the rootkit infection.

Response Times tests attempt to determine how quickly an anti-malware vendor responds to a new threat with their definition updates and heuristic detections.

Individually, each of these tests gives us a way to gauge one of the many facets of measuring the value of an anti-malware product. However, when grouped together, they can give a holistic picture of how well we balance the many criteria by which we are judged.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (2)

  • Mr Critic January 29, 2008 5:07AM

    Congratulations on doing so well. Perhaps people would also like to look at a comparison of security products here – http://www.techsupportalert.com/review-security-guards.htm and comment

  • Pillsbury January 28, 2008 8:03AM

    Props to you guys for publishing your results on your own blog even with the ding for response times. Personally I think a 6-8 hour response time is not bad at all. I assume it meant 6-8 hours after it is confirmed malware by either McAfee or other industry peers. With the volume of malware that has to be analyzed/processed/detected I say not too shabby gents, not too shabby at all.

    Also, too bad the opportunity to snipe ole CMantis in COD4 (previously 1,2) has diminished, I believe the new version would be a good test of our keyboard kung fu.

    Good work guys!
    Abhishek be quiet.