Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 10, 2009, 09:28:43 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
341432
Posts
37736
Topics
85674
Members
Latest Member:
bilbo2
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Melih's Corner - CEO Talk/Discussions/Blog
Service to human race or fame seeking selfishness?
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: Service to human race or fame seeking selfishness? (Read 20821 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8316
Service to human race or fame seeking selfishness?
«
on:
September 13, 2008, 07:56:32 AM »
The way the
AV Test's
are done: Are they really of benefit to users?
Click to read
and please let me have your say on this.
thanks
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
John Buchanan
Global Moderator
Comodo's Hero
Offline
Posts: 2587
Behold, there be Dragons here!
Re: Service to human race or fame seeking selfishness?
«
Reply #1 on:
September 13, 2008, 08:51:26 AM »
That is a good point, Melih. Well spoken and directed towards the people who can help the most - those with viruses unknown to the security companies.
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8316
Re: Service to human race or fame seeking selfishness?
«
Reply #2 on:
September 13, 2008, 09:16:05 AM »
Quote from: John buchanan on September 13, 2008, 08:51:26 AM
That is a good point, Melih. Well spoken and directed towards the people who can help the most - those with viruses unknown to the security companies.
Indeed.
They should release all malware to all AV companies asap (if they have them, as noone has been able to confirm that they do have what they say but lets assume they do).
And then test the "Capability" of the AV!
Capability could be: Types of malware caught, speed of the AV on user's machine, speed of signature creation and so on. these are the things that could differentiate AV products.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Star Shadow
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 286
Re: Service to human race or fame seeking selfishness?
«
Reply #3 on:
September 13, 2008, 10:16:38 AM »
This is a big what if ... what if the AV companies do have the same samples as the testers already, but the product's scanning engine is incapable of detecting it for some reason or another? It's one thing to have the sig of a virus, but it's another thing to detect it buried deep in an executable. There is a lot of malware out there, but I am sure that AV companies have a good sampling of them, and I am sure that most AV testers would have all the samples they can find, and if they can find it then a large AV company with thousands of users would have said malware submitted to them.
But, you bring up good points. The quality of the AV product is how fast it can run and how many baddies it can find. Since there are a lot of malware out there that is unknown, AVs need to be really smart about how an application is behaving. It needs to have some form of HIPS and some other mechanisms that know what is bad and what is good. Since not all the malware out there is known.
Then again, maybe some companies have a smaller set of malware to work with, but I think some just don't have the capability of detecting the malware. So, to fully see if this is the case, one needs to compare the list of malware sigs in each AV program to each other to see how they differ and then those lists need to be compared to the list the AV testers use. Only then will we see who has the greater list of malware and we can see if the tester uses malware that the company does not have. However, if the tester is using malware that is in each AV program's database, then it really is a true test of how well the program can actually detect what it knows is to be bad.
Cheers.
Logged
I'm getting Married!!!
Xman
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 719
Xman
Re: Service to human race or fame seeking selfishness?
«
Reply #4 on:
September 13, 2008, 12:01:40 PM »
Hi Melih, BTW really nice work on CIS, I still believe the Whitelist & block all others pending verification is the way to go especially if you reintegrate Threatcast to CIS, you will facilitate this for yourselves & all the users' of CIS because strength in numbers is a real fact of life and you already have
THE
Firewall everybody else wished they could have developed but couldn't, so in short reintroduce Threatcast along with heuristics in CIS & fly high forever, always remember your set goal of prevention over detection...
Cheers to you and the guys
Xman
«
Last Edit: September 13, 2008, 12:07:51 PM by Xman
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Service to human race or fame seeking selfishness?
«
Reply #5 on:
September 13, 2008, 12:48:26 PM »
I plenty agree.
Quote from: gibran on June 27, 2008, 09:43:46 AM
I would like to add also one joint sample gathering organization
There will be obviously difference in AV engines but having all brands excange new samples will improve the current situaltion a lot and spare us the need to use online multi AV scan sites
If possible I wish Comodo to Launch some AV alliance Consortium and actively promote this joint-operation to the fullest. (L)
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Xman
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 719
Xman
Re: Service to human race or fame seeking selfishness?
«
Reply #6 on:
September 13, 2008, 01:18:10 PM »
Hi Gibran, agreed and stupid to say with Rising in China which I had been using till CIS release & miss somehow since 30.6% of all malware created originates from China,
www.threatexpert.com
Would be a great collaboration IMO!
PS: Never caught an infection during its' use in last 4 months prior to currrent roadtest of CIS now and with CIS still not infected to date, I do however sorely miss some of the great features in Risings' AV, like time remainng to scan, a progress bar, custom scan configurations, flexible virus definitions update scheduling, etc...
Cheers
Regards
Xman
«
Last Edit: September 13, 2008, 01:27:58 PM by Xman
»
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8316
Re: Service to human race or fame seeking selfishness?
«
Reply #7 on:
September 13, 2008, 01:27:40 PM »
Quote from: Xman on September 13, 2008, 12:01:40 PM
Hi Melih, BTW really nice work on CIS, I still believe the Whitelist & block all others pending verification is the way to go especially if you reintegrate Threatcast to CIS, you will facilitate this for yourselves & all the users' of CIS because strength in numbers is a real fact of life and you already have
THE
Firewall everybody else wished they could have developed but couldn't, so in short reintroduce Threatcast along with heuristics in CIS & fly high forever, always remember your set goal of prevention over detection...
Cheers to you and the guys
Xman
Thanks Xman...yep.. thats the next CIS version!
Threatcast plus few other goodies
watch this space..
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Xman
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 719
Xman
Re: Service to human race or fame seeking selfishness?
«
Reply #8 on:
September 13, 2008, 01:31:00 PM »
Hi Melih!, good stuff! read my prior post moments ago to Gibran, I think it's important...
Xman & cheers
«
Last Edit: September 13, 2008, 01:40:49 PM by Xman
»
Logged
Xman
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 719
Xman
Re: Service to human race or fame seeking selfishness?
«
Reply #9 on:
September 13, 2008, 01:47:17 PM »
Quote from: Melih on September 13, 2008, 01:27:40 PM
Thanks Xman...yep.. thats the next CIS version!
Threatcast plus few other goodies
watch this space..
Melih
Would Dec 2008-Jan 2009 be optimistic?
Regards
Xman
«
Last Edit: September 13, 2008, 01:49:21 PM by Xman
»
Logged
3xist
Guest
Re: Service to human race or fame seeking selfishness?
«
Reply #10 on:
September 14, 2008, 12:35:57 AM »
Quote from: Xman on September 13, 2008, 01:47:17 PM
Would Dec 2008-Jan 2009 be optimistic?
Regards
Xman
Yep.
Josh
Logged
3xist
Guest
Re: Service to human race or fame seeking selfishness?
«
Reply #11 on:
September 14, 2008, 12:42:42 AM »
I 100% Agree with your Blog, Melih.
Selfishness of AV Testers is a big problem.
Poll Made:
AV Testing: Service or Selfishness?
Josh
«
Last Edit: September 14, 2008, 12:49:06 AM by 3xist
»
Logged
Star Shadow
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 286
Re: Service to human race or fame seeking selfishness?
«
Reply #12 on:
September 15, 2008, 01:33:43 PM »
Melih,
You have a security testing site for firewalls and HIPS (
http://www.testmypcsecurity.com/
). The name of that address doesn't specifically say firewall, so are you going to give thought to adding a AV section to that site since Comodo now has a a great AV technology that will become great?
My thoughts are, like I mentioned earlier in this thread, that if all the AVs are tested against known malware and their malware databases are compared to others to see if they contain the same items, then it is a fair test. The AV part of the site would be just like the Firewall part and have all tests freely available so that all AV companies, if they decide to, can download the samples and improve upon their own product. The site would have all known baddies for the samples in multiple forms, like some embedded in pictures and some embedded in exes and so forth. This would provide fairness.
Some things the results needs to show for the AV test are as follows: Speed of the scan, processor and memory usage, detection rate, a list of all baddies in the test that are not in the sigs for that AV, the percentage of how many baddies are found that are in the AVs database -- in other words, how good the engine is to pick up a baddie that it is suppose to know about. Maybe some other infos that I thought of. The engine speed and quality tests are probably the most important, because if the engine is really slow and only picks up a few baddies, then the AV is useless, but if the Engine is really fast and it actually detects all the baddies that it has definitions for, then that is a great AV, so a ratio of speed to known baddie detection rate is good way to see the quality of the product. If the know baddie list is small, but it detects 100% of the malware, then that company should be notified and they can crap the complete known baddie file from the site and add the definitions.
This would help other AVs, and your competition, but on the other hand, people tend to be stuck on certain products and will not budge from using them no matter what anyone says, so if the companies play ball and get the data from your site, then that helps out everyone, thus making the web safer for everyone.
Also, the effectiveness of complete security suites should be listed as well, like with the individual AVs and Firewalls, so then people can see how much resources some suites use and how well they protect you as a whole. Matousec doesn't do suites and that is something that should be done since I have read comments from some vendors saying that their product works best as a suite. This would test their claim. Test my PC security should be all product ranges.
It would be the ultimate one stop place.
Is this an idea?
Logged
I'm getting Married!!!
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8316
Re: Service to human race or fame seeking selfishness?
«
Reply #13 on:
September 15, 2008, 04:13:58 PM »
Yes indeed.
We have been thinking about how to test if a product "protect" you or not. Its not about detection its about "protection". What we want to do is to protect ourselves from baddies and we don't really care how its done as long as its done. Hence there are different types of methods that we should be able to test. Lets see..
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
John Buchanan
Global Moderator
Comodo's Hero
Offline
Posts: 2587
Behold, there be Dragons here!
Re: Service to human race or fame seeking selfishness?
«
Reply #14 on:
September 15, 2008, 10:54:53 PM »
Quote from: Star Shadow on September 15, 2008, 01:33:43 PM
Melih,
You have a security testing site for firewalls and HIPS (
http://www.testmypcsecurity.com/
).
I went to that site, read the pages, and attempted to DL the all_tests.zip file. Both CIS and Avast (seperately and on different parts) claim it contains harmful viruses (CIS wanted to block the file, Avast asked to terminate the connection).
I am asking to confirm these are actually clean and not false alarms. Thank you.
Logged
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.076 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com