Security Incidents mailing list archives
Re: Possible Mail server compromise ?
From: Paul Schmehl <pauls () utdallas edu>
Date: Thu, 21 Feb 2008 11:13:42 -0600
--On Thursday, February 21, 2008 11:31:02 +0100 "Faas M. Mathiasen" <faas.m.mathiasen () googlemail com> wrote:
Dear Valdis, Interesting, have you compared your results with another scanner ? If you just scan with ClamAV you can't obviously really tell what you missed that other scanners found.
We once did a side by side test at our mail gateway using McAfee, ClamAV and Sophos. All three scanners were automatically updated (checked for updates and installed them if found) every hour. All three scanners got the exact same mail stream (in other words, no one scanner saw anything or didn't see anything that the other scanners saw).
The results were (from memory) something like 99.1% detection rate for McAfee, 98.9% for ClamAV and 87.6% for Sophos. Occasionally there would a virus that McAfee caught that ClamAV did not, and vice versa. There was never anything that only Sophos caught.
That test was three or four years ago, so it's meaningless now except for the datapoint that you can trust ClamAV just as much as you trust McAfee. Unfortunately AV-comparatives doesn't test ClamAV or Sophos, so they don't have any recent side by side results for them. (Popular magazine tests are just about useless.)
-- Paul Schmehl (pauls () utdallas edu) Senior Information Security Analyst The University of Texas at Dallas http://www.utdallas.edu/ir/security/
Current thread:
- Re: Possible Mail server compromise ?, (continued)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 19)
- Re: Possible Mail server compromise ? Bob Toxen (Feb 19)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 19)
- Re: Possible Mail server compromise ? Valdis . Kletnieks (Feb 20)
- Re: Possible Mail server compromise ? Bob Toxen (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 20)
- Re: Possible Mail server compromise ? Eygene Ryabinkin (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 20)
- Re: Possible Mail server compromise ? Valdis . Kletnieks (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 21)
- Re: Possible Mail server compromise ? Paul Schmehl (Feb 21)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 19)
- Re: Possible Mail server compromise ? Jon Oberheide (Feb 20)
- Re: Possible Mail server compromise ? Valdis . Kletnieks (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 20)
- Re: Possible Mail server compromise ? Peter Kosinar (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 21)
- RE: Possible Mail server compromise ? Richard C Lewis (Feb 22)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 26)
- Re: Possible Mail server compromise ? Eduardo Tongson (Feb 20)
- Re: Possible Mail server compromise ? Faas M. Mathiasen (Feb 20)
- Re: Possible Mail server compromise ? Eduardo Tongson (Feb 21)