About Malware Testing

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    About Malware Testing - Presentation Transcript

    1. About Anti-Virus Testing Dr. Vesselin Bontchev, anti–virus researcher FRISK Software International Thverholt 18, IS-105 Reykjavik, ICELAND National Laboratory of Computer Virology Bulgarian Academy of Sciences Acad. G. Bontchev Str., Bl. 2, 1113, BULGARIA E–mail: [email_address]
    2. About Anti-Virus Testing
      • Why Are You Here?
        • You’re an AV tester
          • But if you don’t already know how to do AV testing, how can you be an AV tester?
        • You’re an AV developer
          • But if you don’t already know how to test your own product… Well, let’s leave it at that
        • You like Icelandic weather/food/beer
          • But that is unlikely
        • So, let’s assume that you want to become an AV tester, or to improve your work
    3. So, How Do You Test AV Products?
      • First, you need AV products
        • That’s less trivial than it sounds
      • Then you have to decide what to test
        • Product type
          • Scanner, integrity checker, behavior blocker, suite…
        • Operation method
          • On-demand, on-access, both
        • Platform
          • Operating system, device, clean, infected, under attack, etc…
        • Properties to test
          • Detection, disinfection, identification, speed, false positives, usability, etc.
        • Test set
          • Not necessarily a virus collection!
    4. More “How-to” Stuff
      • Then, You Have to Figure Out How to Use the AV Products You Have
        • That’s even less trivial than it sounds!
          • Usually you do the wrong thing as early as during the installation phase
          • Talk to the developers! Trust me, they know better than you how their products are supposed to be used
      • Then You Have to Build Your Test Set
        • Getting it from the WLO is not “it”
        • Neither is downloading it from a Vx site
        • More (much more) about this - later
    5. Even More “How-to” Stuff
      • Then You Have to Publish Your Testing Methodology
        • You have one, right? Right?!
        • Prepare for it to be shot down by the more knowledgeable than you
        • So that you’ll have to revise it completely
        • And, no, you can’t do it right the first time
      • Only Then You Can Begin Testing
      • But That’s Not the End!
    6. And Even More “How-to” Stuff
      • Then You Have to Make Sense of the Results
        • Which often don’t make sense
        • Talk to the developers! They know better than you
        • But don’t trust the developers! They are biased towards their own product. Always verify the things yourself
      • Finally, Publish the Results
        • And prepare to be accused of incompetence by developers, users, fellow testers – in other words, by just about anyone
      • Fun, Isn’t It?
        • But, hey, nobody ever said that AV product testing was easy …
      • Questions?

    + frisksoftwarefrisksoftware, 3 years ago

    custom

    1341 views, 0 favs, 8 embeds more stats

    Presented at the International Antivirus Testing Wo more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 1341
      • 865 on SlideShare
      • 476 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 899
    Most viewed embeds
    • 450 views on http://www.f-prot.com
    • 14 views on http://rogerspeaking.blogspot.com
    • 4 views on http://seguridad-informacion.blogspot.com
    • 4 views on http://rogerspeaking.com
    • 1 views on http://64.233.179.104

    more

    All embeds
    • 450 views on http://www.f-prot.com
    • 14 views on http://rogerspeaking.blogspot.com
    • 4 views on http://seguridad-informacion.blogspot.com
    • 4 views on http://rogerspeaking.com
    • 1 views on http://64.233.179.104
    • 1 views on https://s3.amazonaws.com
    • 1 views on file://
    • 1 views on http://72.14.235.104

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories