Latest AV product rankings from SRI Malware Threat Center

  • Thread starter Thread starter Oliver Costich
  • Start date Start date
Oliver said:

Too bad it doesn't mention whether a test for a particular anti-virus
product was a free or paid version. Presumably all of the AV products
listed are the paid version. Would be interesting to see how similar or
dissimilar would be the rankings if both free and paid versions were
included in the list.
 
From: "VanguardLH" <[email protected]>



| Too bad it doesn't mention whether a test for a particular anti-virus
| product was a free or paid version. Presumably all of the AV products
| listed are the paid version. Would be interesting to see how similar or
| dissimilar would be the rankings if both free and paid versions were
| included in the list.

I know SRI personnel as I work with them.

However, I must state that the test has a *major* flaw. It is ONLY based upon a catch
rate as noted by...
"1. All antivirus binary analysis results are provided via www.virustotal.com. "

Detecting malware is one thing, actually removing it is another. Therefore the results
are limited at best.

Of course, there is no opportunity for removal if there is no
detection, so the results indicate which are best at that stage of the
malware threat evasion.


The other flaw is it doesn't account for false positives, so as they
point out, a program that marked every file as containing a virus
would be the winner. The companies on the list do better than that,
I'm sure.
One good thing that has come from SRI is BotHunter.
http://www.bothunter.net/

Bothunter is dynamite. I think it would get more use if it were better
documented in terms of what it tells you.
 
VanguardLH said:
Oliver Costich wrote:
Too bad it doesn't mention whether a test for a particular anti-virus
product was a free or paid version. Presumably all of the AV products
listed are the paid version. Would be interesting to see how similar or
dissimilar would be the rankings if both free and paid versions were
included in the list.


It might also be helpful to see the version numbers for all of the AV
products. The only two version numbers that I saw were for AhnLab v3 and
NOD32 v2. I thought that was curious since NOD has had v3 out for quite
some time now.
 
Back
Top