funsec mailing list archives

RE: Consumer Reports Slammed for Creating 'Test' Viruses


From: "David Harley" <david.a.harley () gmail com>
Date: Thu, 17 Aug 2006 20:09:47 +0100

I think "retrospective" is the apt term; "proactive" doesn't fit the
definition. 

I agree it sounds odd. I imagine that it's used because it tests 
proactive detection rather than near-exact identification.

I've been in the position of testing heuristic AV protection and 
what CR did is very tempting. I considered it and was talked out 
of it. The alternatives weren't very good.

Granted, we probably don't have the very best methodology down
yet. But creating variants is a minefield.

-- 
David Harley
Security Author & Consultant
Small Blue-Green World
dharley () smallblue-greenworld co uk





Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.eweek.com/blogs/larry%5Fseltzer/
Contributing Editor, PC Magazine
larryseltzer () ziffdavis com 

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.405 / Virus Database: 268.11.1/421 - Release Date: 16/08/2006
 

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: