Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 18, 2013, 09:38:59 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668806
Posts
71126
Topics
145740
Members
Latest Member:
sushil kumar
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Other Security Products
Retrospective Test November 2011
« previous
next »
Pages:
[
1
]
Author
Topic: Retrospective Test November 2011 (Read 11559 times)
GOA
Comodo's Hero
Offline
Posts: 478
Retrospective Test November 2011
«
on:
November 20, 2011, 03:48:28 PM »
New Retrospective Test (Heuristic) from av-comparatives
http://www.av-comparatives.org/en/comparativesreviews/detection-test
Logged
CF 6.1.275152.2801
Windows 7 x64
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Retrospective Test November 2011
«
Reply #1 on:
November 20, 2011, 06:39:27 PM »
Just to help cross posting:
Wilders:
http://www.wilderssecurity.com/showthread.php?t=312396
and
http://www.wilderssecurity.com/showthread.php?t=312445
avast justification of the poor qualification:
http://forum.avast.com/index.php?topic=88672.msg709388#msg709388
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Retrospective Test November 2011
«
Reply #2 on:
November 21, 2011, 01:12:17 AM »
Quote from: Tech on November 20, 2011, 06:39:27 PM
avast justification of the poor qualification:
http://forum.avast.com/index.php?topic=88672.msg709388#msg709388
That's a pretty weak justification... In other words, once something gets to your machine, you can pretty well write Avast off...
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
panic
Global Moderator
Comodo's Hero
Online
Posts: 11203
Linux is free only if your time is worthless.;-)
Re: Retrospective Test November 2011
«
Reply #3 on:
November 21, 2011, 02:05:41 AM »
Quote from: HeffeD on November 21, 2011, 01:12:17 AM
That's a pretty weak justification... In other words, once something gets to your machine, you can pretty well write Avast off...
But interesting to note that their focus is shifting to prevention as opposed to detection.
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you can't conform, don't use the forum.
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Retrospective Test November 2011
«
Reply #4 on:
November 21, 2011, 02:10:53 PM »
Quote from: HeffeD on November 21, 2011, 01:12:17 AM
That's a pretty weak justification... In other words, once something gets to your machine, you can pretty well write Avast off...
If a driver is loaded, nothing can be done, by avast, by CAV, by CIS or by anything else...
It's pretty too late.
Quote from: panic on November 21, 2011, 02:05:41 AM
But interesting to note that their focus is shifting to prevention as opposed to detection.
Interesting uh? I've arise a discussion about that in a reserved part of the forum and it does not go further... or, better, I've got bashed there because I was trying to say that
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6624
Re: Retrospective Test November 2011
«
Reply #5 on:
November 21, 2011, 03:19:28 PM »
Quote from: Tech on November 21, 2011, 02:10:53 PM
If a driver is loaded, nothing can be done, by avast, by CAV, by CIS or by anything else...
It's pretty too late.
So you're saying that all of the malware that wasn't detected by Avast had installed a driver?
Edit: Just to clarify, I'm not trying to be accusing, I'm just curious. I haven't looked at the results of the test.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Retrospective Test November 2011
«
Reply #6 on:
November 22, 2011, 05:39:51 AM »
Quote from: HeffeD on November 21, 2011, 03:19:28 PM
So you're saying that all of the malware that wasn't detected by Avast had installed a driver?
No, I'm not an insider from av-comparatives
What I can say, now, is that the av-comparatives team (IBK) has posted in avast forum and specifically mention it (
http://forum.avast.com/index.php?topic=88672.msg710147#msg710147
).
Quote from: HeffeD on November 21, 2011, 03:19:28 PM
Edit: Just to clarify, I'm not trying to be accusing, I'm just curious. I haven't looked at the results of the test.
No problems HeffeD. You're welcome.
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Retrospective Test November 2011
«
Reply #7 on:
November 22, 2011, 07:42:37 AM »
Hi Vlk, I disagree with you.
1) only about the half is pointing directly to binaries/files. The rest are exploits. In your misses you for sure also encountered some exploits and not only direct links. The "problem" is (and it is even written in the report) that practically all products (including of course Avast) are good are blocking/detecting exploits/drive-by downloads. That's also why the % are so high. If you look at the latest research of Microsoft, the biggest issue for users are not 0-day exploits (according to their paper its even close to 0%) but social-engineered malware, which includes also tricking users in clicking on links pointing to files. If you miss malware from the web, the test will and does reflect that. But I am glad to hear that the next version will improve further in this regard.
2) too less samples: others use 10 samples for such a test and base ratings based on that. We use usually 50x that size. Arguing that sample size is too small doesn't sound fair. If it would be 1 million someone would say "who surfs to 1 million malicious sites...?" missing the whole point.
3) How user-dependent cases are interpreted is up to the user. I do not believe that a product which would ask the user for everything should get the same like a product which is able to distinguish between malware and goodware without letting the decision up to the user. Anyway, only on chart2 you can sort based on the green bar. In chart3 you can combine blocked+userdependent.
4) I expected that also Whole Product Dynamic Tests would be criticized (like any other test) in future if the scores are unfavorable for someone, despite the internal promotion for such sophisticated tests.
*****************************************
the above is, I am assuming from av comparitives.....
few things require clarification:
"social-engineered malware, which includes also tricking users in clicking on links pointing to files."
what do you call this when its brand new if not Zero day malware?
""who surfs to 1 million malicious sites...?" missing the whole point."
Who has 1M malware in their computer??? but they do their detection testing with 1M malware??? I don't understand the logic they are presenting here as it contradicts what they do with detection testing.
When will they have the capability to test "innovation" like CIS with its "Automatic Sandboxing"?
Spreading these old style tests is old now....give users information about what matters which is "Protection" not "detection" by putting dead viruses on your HD and then detect them using Antivirus.....Seriously...lets get serious about Testing. And testing should be FREE!!!! Any financial relationship between testing organisation and AV companies could be seen as a negative. Testing organisations getting money from AV companies should be changed.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
spainach_12
Comodo's Hero
Offline
Posts: 458
Re: Retrospective Test November 2011
«
Reply #8 on:
November 23, 2011, 01:23:51 AM »
I have a few hunch...
Quote from: Melih on November 22, 2011, 07:42:37 AM
"social-engineered malware, which includes also tricking users in clicking on links pointing to files."
what do you call this when its brand new if not Zero day malware?
Social-engineering has been around for quite a long time. Maybe not for computers, but I suppose this kind of attacks are common and has been around for quite some time, only unrecognized since their "malware-ness" so to speak was back then, hardly threatening. I remember back in 2009, there was a site advertising a product as a legitimate, even stellar antivirus. Turns out it was a sham. It does a fake scan and nothing more. My brother was fooled. In this sense, they're not zero-day, are they?
Quote from: Melih on November 22, 2011, 07:42:37 AM
""who surfs to 1 million malicious sites...?" missing the whole point."
Who has 1M malware in their computer??? but they do their detection testing with 1M malware??? I don't understand the logic they are presenting here as it contradicts what they do with detection testing.
Well, in this sense I'm supposing that malicious sites are entities different from malware residing in your system. What I'm saying is that by using 1M local test samples, you're stressing the capacities of the av being tested. Though unrealistic, it does have some sense to strain a product to find out its limits.
On the other hand, a million malicious sites isn't quite necessary since the malicious codes for sites aren't really that much varied, or am I mistaken? In this view, you can test, for example, 10 different kinds of sites and they can represent as much as 1M others. Malware, however, are varied (and very much so) and much more complex in coding, hence, 1M malware may have individual properties that define them from other malware.
Quote from: Melih on November 22, 2011, 07:42:37 AM
When will they have the capability to test "innovation" like CIS with its "Automatic Sandboxing"?
Spreading these old style tests is old now....give users information about what matters which is "Protection" not "detection" by putting dead viruses on your HD and then detect them using Antivirus.....Seriously...lets get serious about Testing. And testing should be FREE!!!! Any financial relationship between testing organisation and AV companies could be seen as a negative. Testing organisations getting money from AV companies should be changed.
Old as they may be, I still find them rather relevant as they do show you the capacity of AV's in case of emergencies. Prevention is indeed a better option, but it is not expected that every malware can be prevented. This is still as serious as it can be because if every other av company focused on prevention, and it so happens that by some misfortune a prodigious cracker manages to slip a virus inside computers, then what of the capacities of the av's to remedy such things? What would become of the users?
Yet, in spite of all these, I must agree that financial relationships do mar the lines between business and honest testing of products. I do not suggest that paying for being tested should be altogether discarded or worse, banned (what they're doing is a form of advertising after all, and advertisements should be paid. Moreover, testing becomes less serious since no benefit on the behalf of the tester is gained from this. Hence, testing would be done however questionable the means and nothing can be said about it. A few might make the charitable deed, but sooner or later, that'll come to an end). What I am suggesting is that av-comparatives change the mode of payment and/or state the transactions that were made (were the payments equal? who tested the av's and are they credible? are they part of av-comparatives?) and the mechanics of this financial relationship, or they can offer a free, but limited version of testing. In this, we could limit one cause of doubt.
well, these are all just a bunch of hunch.
I'm not claiming any expertise in this field nor have I any solid proof of what I have claimed. I have only deduced from what I have come to learn in my experience and from what I have previously read. Hopefully, you won't hold it against me from trying.
Have a nice day.
Logged
If you want to change the system, you need to learn how to break it.
Windows 7 Starter dualboot PeppermintOS | Windows Firewall | NTFS File Permissions | Commandline | Common Sense
spainach_12
Comodo's Hero
Offline
Posts: 458
Re: Retrospective Test November 2011
«
Reply #9 on:
November 23, 2011, 01:26:27 AM »
Oh, and on a side-note, each time I refer to variation of codes, I refer to the variation of
known
codes.
Logged
If you want to change the system, you need to learn how to break it.
Windows 7 Starter dualboot PeppermintOS | Windows Firewall | NTFS File Permissions | Commandline | Common Sense
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Retrospective Test November 2011
«
Reply #10 on:
November 27, 2011, 09:29:04 AM »
http://forums.comodo.com/melihs-corner-ceo-talkdiscussionsblog/avcomparativesorg-bullying-and-financial-deals-with-anti-virus-vendors-t78869.0.html;msg564687#msg564687
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
spainach_12
Comodo's Hero
Offline
Posts: 458
Re: Retrospective Test November 2011
«
Reply #11 on:
November 28, 2011, 09:32:33 PM »
Quote from: Melih on November 27, 2011, 09:29:04 AM
http://forums.comodo.com/melihs-corner-ceo-talkdiscussionsblog/avcomparativesorg-bullying-and-financial-deals-with-anti-virus-vendors-t78869.0.html;msg564687#msg564687
While it's saddening for them to get a wee bit greedy (though I'm not altogether discarding the possibility of a miscommunication seeing so many instances of possible variations of meanings in statements), I still stand-by what I said that it is still recommended for payments to be made. It's just that the mechanics they employ/implore are unsuitable, even perhaps grievously faulty. Disappointing, yes it is.
Logged
If you want to change the system, you need to learn how to break it.
Windows 7 Starter dualboot PeppermintOS | Windows Firewall | NTFS File Permissions | Commandline | Common Sense
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Retrospective Test November 2011
«
Reply #12 on:
November 29, 2011, 07:35:02 AM »
Quote from: spainach_12 on November 28, 2011, 09:32:33 PM
While it's saddening for them to get a wee bit greedy (though I'm not altogether discarding the possibility of a miscommunication seeing so many instances of possible variations of meanings in statements), I still stand-by what I said that it is still recommended for payments to be made. It's just that the mechanics they employ/implore are unsuitable, even perhaps grievously faulty. Disappointing, yes it is.
AV-Comparatives Force AntiVirus vendors to deny even existence of a financial deal between them. Why?
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
WinDefend
Comodo Member
Offline
Posts: 26
Re: Retrospective Test November 2011
«
Reply #13 on:
November 29, 2011, 12:34:47 PM »
AV-C's reply to Comodo:
http://www.av-comparatives.org/forum/index.php?page=Thread&threadID=1054
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Retrospective Test November 2011
«
Reply #14 on:
November 29, 2011, 01:45:06 PM »
Andreas of AV-Comparitives said: "When I (Andreas) started doing the public tests in 2003, I did it for free and asked users if they wanted to donate something. Practically no one donated, and based on the high demand for continuing the tests, and the increasing complexity of the tests, I had to start asking all vendors to pay a fee."
But why do they force the Antivirus companies to deny the "existence" of the financial relationship? Why are they trying to hide this?
Here is the clause look at the highlighted section.
Why are they scared of letting public know? How can they be trusted by public if they don't trust public with this information in the first place?
av-comparativesdenyingexistence.png
(92.64 KB, 837x116 - viewed 32 times.)
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.058 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com