funsec mailing list archives

RE: Consumer Reports Slammed for Creating 'Test' Viruses


From: security curmudgeon <jericho () attrition org>
Date: Thu, 17 Aug 2006 13:55:09 -0400 (EDT)



On Thu, 17 Aug 2006, Blanchard_Michael () emc com wrote:

:  You use the existing viruses that are out there.  In order to be a variant,
: there has to be some similarities that you can produce your pattern sig for.
: 
:   I'll repeat, never, EVER is it warrented to create new viruses for any 
: reason, period.

So, let's say 10,000 viruses exist where any single one has 100 variants. 
How does your pattern match do .. very well against the 100 known and how 
well against the next 100 variants? Does one assume that all the 
documented/public variants are indicative of a diverse set of examples?

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: