funsec mailing list archives

Re: Spam cube


From: Predrag Ivanovic <predivan () ptt yu>
Date: Mon, 27 Mar 2006 22:20:01 +0200

On Mon, 20 Mar 2006 09:12:15 +1200
Nick FitzGerald wrote:

Predrag Ivanovic to Drsolly to ???:

percent of viruses discovered/removed? 

You would not believe how difficult this one is to measure.

IIRC,methodology used for one of the reviews was:
1.put as many malware on computer as you can

As Alan has already indicated, you make that sound so easy...

Well,I've seen quite a few users who managed to collect 2000+ viruses,
without even knowing,so it's not *that* hard :-)
Just kidding,I understand  that these "test-cases"(heh) are unusable for any
serious,competent test.  
 
<snip excellent insight to AV testing>


Aside from having had a general to advanced technical interest in all 
AV product testing issues for a large part of the last ~15 years, I 
also worked in independent AV product testing for a couple of years and 
dealt with all these things on an almost daily basis.

I would like to thank you,Nick,Drsolly,and all others that replied in this
thread.
I honestly had no idea how complex this field is and how much work
and expertise it requires.Now,I think I understand a bit better,thanks.
Also,larting all those people that claim that there is " a conspiracy between
AV vendors and virus writers" seems completely justified now,nobody
in their right mind would put this amount of work willingly on themselves :-)
    

Regards,

Nick FitzGerald


Pedja
-- 
 "I came, I saw, I ran away screaming"
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: