The Difference between Track and Testing Performance

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    The Difference between Track and Testing Performance - Presentation Transcript

      • The difference between track and testing performance
      • Roel Schouwenberg, Senior Anti-Virus Researcher
      • Kaspersky Lab Benelux
      • [email_address]
    1. About:Roel
      • Malware analysis
      • AV research
      • Incident response
    2. Overview
      • Testing AV engine
      • Testing AVendor’s response time
      • Product technologies
      • Conclusions
    3. Current testing
      • On-demand
        • WildList (won’t go there)
        • Large (zoo) test bed
      • Retrospective
        • using x month old product
      • On-access (not so common or detailed)
    4. On-demand: obvious flaws
      • Trash files
      • Age of samples
      • Lack of transparency
      • Response time is not a factor
      • Lack of resources to perfect testing
      • Etc.
    5. Infectors / Trojanizers
      • Trojanizers (PE, script)
      • Real infectors
      • Check response time for detection and disinfection
        • Creating trojanizer test bed can take a long time
    6. Online scan services
      • JottiScan, VirusTotal (and others)
      • Much trash and ‘trash’
      • False positive issues
      • Additional checks needed
        • SFX archives and so on
    7. Testing vs track performance
      • Detection on/of packer/crypter
      • Compare results with and without packer detection
      • Differentiate between packers
        • Regular vs custom packer/crypter
        • Generic vs detecting specific family
      • Age of samples
        • 1/2/3/6/12 months old
    8. Differentiate between malware
      • Regional malware
      • Malware coming from a region
      • Payload (Banker vs GameThief trojan)
      • Automagically fabricated samples
        • How many Zlobs do you want in the equation?
    9. Response time
      • Global outbreak
      • Localized outbreak
      • Low priority malware
      • Infectors/trojanizers
    10. Retrospective testing
      • 1 second is enough
      • Modified ‘droppers’
      • Type of samples
    11. Product technologies
      • HIPS-like module
      • Components working together – AV vs IS
      • (Memory scanner)
      • Not so relevant (in this case):
        • Malware removal
        • Registry cleanup
        • Malware detection on infected system
    12. Conclusions
      • Other/nicer ways to check out the competition 
      • Product technologies make testing-life harder
      • Testing will always be flawed
    13. The end
      • Thank you for your attention!
      • Questions or comments?
      • [email_address]

    + frisksoftwarefrisksoftware, 3 years ago

    custom

    855 views, 0 favs, 2 embeds more stats

    Presented at the International Antivirus Testing Wo more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 855
      • 787 on SlideShare
      • 68 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 467
    Most viewed embeds
    • 60 views on http://www.f-prot.com
    • 8 views on http://seguridad-informacion.blogspot.com

    more

    All embeds
    • 60 views on http://www.f-prot.com
    • 8 views on http://seguridad-informacion.blogspot.com

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories