Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 04:04:05 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664076
Posts
70634
Topics
145265
Members
Latest Member:
sharf224
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Anti-Viruspyware (CAVS)
CAVS BETA Corner
CAV3 detection rate test [2008.10.05] - 10.26% [CLOSED]
« previous
next »
Pages:
1
...
12
13
[
14
]
15
16
Author
Topic: CAV3 detection rate test [2008.10.05] - 10.26% [CLOSED] (Read 27124 times)
darcjrt
Malware Research Group
Comodo's Hero
Offline
Posts: 466
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #195 on:
October 05, 2008, 02:18:00 PM »
Quote from: Toxteth O'Grady on October 05, 2008, 02:02:14 PM
This thread is getting veeery long, and the only thing in it that really matters is whether Comodo ads submitted samples to the database in a reasonable time or not, because anything else is unverifiable as things stand.
I'm glad to say the two samples I submitted a few days ago were added with the latest update. It took 5 to 7 days (which may be a bit too long), but the system does work. It can only get better.
That is great news. How did you submit the samples? CIMA? Email? Comodo file Submitter?
Logged
Best Regards,
J
fazio93
Comodo Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2454
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #196 on:
October 05, 2008, 03:12:00 PM »
Quote from: Toxteth O'Grady on October 05, 2008, 02:02:14 PM
This thread is getting veeery long, and the only thing in it that really matters is whether Comodo ads submitted samples to the database in a reasonable time or not, because anything else is unverifiable as things stand.
I'm glad to say the two samples I submitted a few days ago were added with the latest update. It took 5 to 7 days (which may be a bit too long), but the system does work. It can only get better.
I believe Melih said his goal was to get the sig into the database in less than an hour from submitting it.
(V)
Logged
Windows 7 Ultimate 64-bit
CIS 5.12.256249.2599
Please remember to follow the
Forum Policy
.
Star Shadow
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 372
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #197 on:
October 05, 2008, 03:59:03 PM »
Wow! So much fighting in this tread. :| My solution to this whole mess.
solcroft said he will post the proof at the end of the month that he submitted the files to Comodo, so let's all just assume that he will do just that. He will post his daily results. However, to make things fair to others, I suggest that his results are looked at, but you do not need to believe them until the end of the month: if solcroft does in fact post the proof, then then all the results are taken seriously, but if the proof is not posted, then then all the results are not believed by anyone and all the nay-sayers of solcroft will be proven right.
Soooooo let's hold off the harsh words and fighting until the end of the month. Can we wait that long? If solcroft does not post the proof, then you all can say whatever you want about him, however if he does provide proof at the end of the month, I think some people should at least apologize to him.
Is this a fair settlement to all this bickering? So, let's all calm down please.
Logged
Married to a loving wife.
sded
Guest
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #198 on:
October 05, 2008, 04:25:45 PM »
Perhaps to avoid driving away most of the potential CIS/CAVS3 beta users who might otherwise use the product and help to improve it, maybe we can summarize how all of this fits in, since it certainly may not be obvious to the newb. My understanding of it:
1. CAVS3 is a beta product, not intended to meet any particular performance criteria. It is intended to test and incorporate feed back from the users on functionality, utility, etc. It is also the next phase (after CAVS2, which was never released) of collection of the appropriate databases for a fully capable AV over the next 12 months or so. And a platform to incorporate new Comodo ideas for further testing by the users.
2. The prototype on demand scanner previously shown in CFP3 exhibited many false positives, less than satisfactory detection performance. Similar reports occur for the CAVS3/CIS beta. These can be dangerous to your system unless you are careful about backups-I use Acronis True Image frequently. I repeat, THIS IS A BETA.
3. Users of the beta need to understand that is it a beta, and that the key heuristics features (based on D+) are not yet included. The malware data base is also quite preliminary. Those who are comfortable with observing D+ alerts to detect malware should be comfortable with beta testing the product. Others may want to wait for a later release and install only the CIS firewall.
4. Comodo is working to bring the product up to excellent performance, not dependent on pressuring other organizations to give up their proprietary work products to help Comodo leapfrog their current position in the AV business.
5. I am just another user, no connection with Comodo except to volunteer support to users of some of their products. But I am also not a proponent of faith based security protection, and think users need to understand better what they are getting into. And look forward to seeing data presented by both sides of the current discussions to help that understanding.
«
Last Edit: October 05, 2008, 10:15:38 PM by sded
»
Logged
foxman
Comodo Loves me
Offline
Posts: 191
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #199 on:
October 05, 2008, 05:42:16 PM »
Quote from: solcroft on October 05, 2008, 01:04:51 PM
And what makes you think I haven't done that?
Simple, PROVE IT. Not just cheap talk.
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1570
Re: CAV3 detection rate test [2008.10.04] - 0.00%
«
Reply #200 on:
October 05, 2008, 08:38:21 PM »
Quote from: solcroft on October 05, 2008, 09:29:20 AM
Looking at the results, I don't think so. Do you honestly believe that there are only ~700 pieces of malware in circulation for the last 2 years or so, when typical
daily
updates from some vendors easily reach more than twice that number?
By elevating yourself above virtually the whole of the AV industry you lose credibility.Nobody is suggesting that there are only 700 pieces of malware,but since the vast majority of malware are just variants of a limited number of unique originals,this subset is supposedly what is infecting the highest percentage of users.If you know different then please show so and I'll certainly take my hat off to you >>>>>
Secondly I can't find details of your testing methodology on skimming through the vast number of posts in this thread.Do you use a dedicated system or a VM? Are the samples dormant or running?
You do make some valid points on the efficacy of D+ being dependant upon the technical knowledge of the user,I've made the same point myself numerous times.It's been said that this will be addressed in future releases and that dumb HIPS will learn some smarts.
«
Last Edit: October 05, 2008, 09:07:38 PM by andyman35
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5056
A bad workman always blames his tools
Re: CAV3 detection rate test [2008.10.04] - 0.00%
«
Reply #201 on:
October 05, 2008, 11:10:14 PM »
I take this chance for thanking solcroft about the wildlist articles he cited (it was a long reading)
http://www.people.frisk-software.com/~bontchev/papers/wildlist.html
dating back around '00
http://www.sunbelt-software.com/ihs/alex/vb_2007_wildlist_paper.pdf
http://sunbeltblog.blogspot.com/2008/06/wildlist-battles.html
Those paper were written by AV researchers and also Wildlist org members.
The doubts about Wildlist.org's wildlist even address the sample selection requirements although they are not limited to only that:
Quote from:
http://www.sunbelt-software.com/ihs/alex/vb_2007_wildlist_paper.pdf
The WildList only contains intentionally malicious software which is able to self-replicate by infecting other files (viruses) and PCs in a network environment (worms). After someinternal discussions, the WildList coverage was slightly extended to include some known bots, but only those that areable to spread by themselves, excluding the ones that fall more into the backdoor category.
Trojan, dialers(now a rare occurence), potentially unsafe apps don't meet the requirements for Wildlist inclusion. Another important element is the observation that current threats are targeted, regional, web-based and financially motivated.
Most of these articles express doubts about the Wildlist Org methodology and other valid concerns but the idea of a properly compiled wildlist is not rejected per se.
Since the overall focus further restricted on much specific aspects intead of a more general approach I guess this is my last post in this topic.
Even though I would like to ask everyone to moderate their tones from now on.
«
Last Edit: October 05, 2008, 11:35:55 PM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #202 on:
October 06, 2008, 01:17:25 AM »
Quote from: darcjrt on October 05, 2008, 02:18:00 PM
That is great news. How did you submit the samples? CIMA? Email? Comodo file Submitter?
CIMA and email. Just to make sure.
I have to correct myself. The samples may have been added anywhere between 3 to 7 days after submitting them. I forgot to check for a few days.
Logged
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #203 on:
October 06, 2008, 03:04:03 AM »
Just found two more pieces of malware embedded in websites. I scanned both files over at Jotti.
- The first file had been scanned before, and yet not all AVs detected it (including some of the big names).
http://img375.imageshack.us/my.php?image=pdfpq5.gif
- The second file had not been scanned before. Again, look at how many scanners missed it:
http://img375.imageshack.us/my.php?image=trojanos9.gif
Comodo AV also missed it, but this is what D+ did:
http://img375.imageshack.us/my.php?image=comodomf9.gif
«
Last Edit: October 06, 2008, 03:08:06 AM by Toxteth O'Grady
»
Logged
3xist
Guest
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #204 on:
October 06, 2008, 03:07:08 AM »
Quote from: Toxteth O'Grady on October 06, 2008, 03:04:03 AM
Just found two more pieces of malware embedded in websites. I scanned both files over at Jotti.
- The first file had been scanned before, and yet not all scanners detected it (including some of the big names).
http://img375.imageshack.us/my.php?image=pdfpq5.gif
- The second file had not been scanned before. Again, look at how many scanners missed it:
http://img375.imageshack.us/my.php?image=trojanos9.gif
Comodo AV also missed it, but this is what D+ did:
http://img375.imageshack.us/my.php?image=comodomf9.gif
Hey Toxteth O'Grady
Nice image of D+! As you can see... Prevention should be your first line of Defense! Do you mind sending me this malware?
Thanks
Josh
Logged
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #205 on:
October 06, 2008, 03:11:10 AM »
Quote from: 3xist on October 06, 2008, 03:07:08 AM
Hey Toxteth O'Grady
Nice image of D+! As you can see... Prevention should be your first line of Defense! Do you mind sending me this malware?
Thanks
Josh
The last link to uploaded malware I posted in the forum was deleted.
I'll PM a link, wait a few minutes.
Edit:
PM sent (at least, I hope it worked). Three samples.
«
Last Edit: October 06, 2008, 03:24:39 AM by Toxteth O'Grady
»
Logged
solcroft
Comodo Loves me
Offline
Posts: 146
Re: CAV3 detection rate test [2008.10.04] - 0.00%
«
Reply #206 on:
October 06, 2008, 04:29:16 AM »
Quote from: andyman35 on October 05, 2008, 08:38:21 PM
By elevating yourself above virtually the whole of the AV industry you lose credibility.
Well, that's a pretty amazing accusation, since if you actually read the links I provided you'll find out it's the AV industry who's pointing out that the WildList is obsolete. You make it sound like as though the industry is singing praises about the WildList, but I know better than them.
Quote from: andyman35 on October 05, 2008, 08:38:21 PM
Secondly I can't find details of your testing methodology on skimming through the vast number of posts in this thread.Do you use a dedicated system or a VM? Are the samples dormant or running?
Live system, samples are not executed. Your first question makes no difference to the results, and the second is kind of a no-brainer.
Quote from: gibran on October 05, 2008, 11:10:14 PM
Most of these articles express doubts about the Wildlist Org methodology and other valid concerns but the idea of a properly compiled wildlist is not rejected per se.
As I previously said, it's the results the WildList produces that are out of touch with reality. The intent is good, but to properly carry out that intent with any measure of effectiveness will most probably require a complete overhaul of the methodology.
Quote from: 3xist on October 06, 2008, 03:07:08 AM
As you can see... Prevention should be your first line of Defense!
So why is D+ using detection instead of prevention in that image instead?
Logged
3xist
Guest
Re: CAV3 detection rate test [2008.10.04] - 0.00%
«
Reply #207 on:
October 06, 2008, 04:35:59 AM »
Quote from: solcroft on October 06, 2008, 04:29:16 AM
So why is D+ using detection instead of prevention in that image instead?
Because there are more technologies then you think in D+. It's not a classical HIPS, An Above average developer can make a classical HIPS in 2 weeks, D+ took time. "Detecting" something based on prevention rule-based tech, and other tech in D+ is normal behavior.
Josh
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #208 on:
October 06, 2008, 04:38:50 AM »
D+ has hueristics that
help
you decide whether it is bad or not. They are rarely wrong +
That was a firewall alert
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
3xist
Guest
Re: CAV3 detection rate test [2008.10.05] - 10.26%
«
Reply #209 on:
October 06, 2008, 04:43:11 AM »
Quote from: Kyle on October 06, 2008, 04:38:50 AM
D+ has hueristics that
That's one technology.
By the way solcroft, You can read CFP 3's
benefits
too.
Josh
Logged
Tags:
Pages:
1
...
12
13
[
14
]
15
16
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.267 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com