Security Incidents mailing list archives

Re: Possible Mail server compromise ?


From: Paul Schmehl <pauls () utdallas edu>
Date: Thu, 21 Feb 2008 11:13:42 -0600

--On Thursday, February 21, 2008 11:31:02 +0100 "Faas M. Mathiasen" <faas.m.mathiasen () googlemail com> wrote:

Dear Valdis,

Interesting, have you compared your results with another scanner ? If
you just scan with ClamAV
you can't obviously really tell what you missed that other scanners found.


We once did a side by side test at our mail gateway using McAfee, ClamAV and Sophos. All three scanners were automatically updated (checked for updates and installed them if found) every hour. All three scanners got the exact same mail stream (in other words, no one scanner saw anything or didn't see anything that the other scanners saw).

The results were (from memory) something like 99.1% detection rate for McAfee, 98.9% for ClamAV and 87.6% for Sophos. Occasionally there would a virus that McAfee caught that ClamAV did not, and vice versa. There was never anything that only Sophos caught.

That test was three or four years ago, so it's meaningless now except for the datapoint that you can trust ClamAV just as much as you trust McAfee. Unfortunately AV-comparatives doesn't test ClamAV or Sophos, so they don't have any recent side by side results for them. (Popular magazine tests are just about useless.)

--
Paul Schmehl (pauls () utdallas edu)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/


Current thread: