funsec mailing list archives

RE: Latest VB 100 test results


From: "Alex Eckelberry" <AlexE () sunbelt-software com>
Date: Thu, 6 Dec 2007 10:30:14 -0500

And in case you're not a subscriber, you can get a gist of what happened
from this article:
 
http://www.pcworld.com/article/id,140315-c,antivirus/article.html
 
Many big-brand security products fail to spot commonly-circulating
malware, testing outfit has Virus Bulletin found in its latest tests.

A total of 17 out of 32 of antivirus products failed the company's
stringent VB100 test, which expects software to detect 100 percent of
the commonly-circulating 'WildList' thrown at it without signalling any
false positives.

Programs failing included those from Sophos
<http://www.pcworld.com/tags/Sophos+plc.html> , Kaspersky, Fortinet
<http://www.pcworld.com/tags/Fortinet+Inc..html> , Trend Micro
<http://www.pcworld.com/tags/Trend+Micro+Inc..html> , CA Home, and PC
Tools, though within this group detection failures varied widely. CA's
Home program scored a disturbingly high 40 misses, while the others
scored from 8 misses down to only one miss for Kaspersky. PC Tools'
Spyware Doctor detected the WildList suite but failed because it falsely
identified two files as malware.

 

(The above is not entirely accurate for PC Tools, which did pass with
their AV product (based on VirusBuster), but not their antispware
product.  And CA's other AV product, eTrust, did pass.)

 

 

 

 

Alex

 

________________________________

From: funsec-bounces () linuxbox org [mailto:funsec-bounces () linuxbox org]
On Behalf Of Alex Eckelberry
Sent: Wednesday, December 05, 2007 5:56 PM
To: funsec () linuxbox org
Subject: [funsec] Latest VB 100 test results



Those of you who are subscribers to VB have probably seen the latest
test results.  The number of entrants that failed the test and the rate
of FPs is pretty unusual.  
 
Yikes.
 
Alex
 
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: