Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 9th, 2009, 10:10 AM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,859
Default Non-signatures/heuristics of AVs/suites, comparison

I've been using the Avira security suite for a while, and for as far as I know it depends, aside from the webguard, on signatures and heuristics.

The high % of detections is very nice, but maybe something is missing.

I remember that McAfee used SystemGuards (some kind of HIPS), although most of it was disabled by default.

Usually I tend to judge AVs/suites on how well they perform in av-comparatives.

I wonder if there is some kind of list of other security features in AVs and suites.

Or perhaps we could create one. I presume there is no independent and objective test of those features ?

99 % detection is very nice, but it doesn't cover new malware for which no signature exists yet.

Btw, I virtually never get infected, and I probably could run without an AV, but I prefer to be prepared.
  #2  
Old October 9th, 2009, 10:37 AM
risl risl is offline
Frequent Poster
 
Join Date: Dec 2006
Posts: 581
Default Re: Non-signatures/heuristics of AVs/suites, comparison

The word "heuristics" usually contains a lot beneath the surface.

"I wonder if there is some kind of list of other security features in AVs and suites."

I don't know if the AV companies want to go into details what is actually happening under the hood and what the engine is actually capable of. Or what kind of technologies are implemented on the lower level.

"99 % detection is very nice, but it doesn't cover new malware for which no signature exists yet. "

This is wrong because in addition to the detection rate achieved by signatures, it is capable of detecting unknown/new malware with some probability by different capabilities of the AV engine(heuristics). This means it is impossible to define accurate detection percentages for some product.
  #3  
Old October 9th, 2009, 04:17 PM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,859
Default Re: Non-signatures/heuristics of AVs/suites, comparison

Quote:
Originally Posted by risl
The word "heuristics" usually contains a lot beneath the surface.

"I wonder if there is some kind of list of other security features in AVs and suites."

I don't know if the AV companies want to go into details what is actually happening under the hood and what the engine is actually capable of. Or what kind of technologies are implemented on the lower level.

"99 % detection is very nice, but it doesn't cover new malware for which no signature exists yet. "

This is wrong because in addition to the detection rate achieved by signatures, it is capable of detecting unknown/new malware with some probability by different capabilities of the AV engine(heuristics). This means it is impossible to define accurate detection percentages for some product.

I once read a paper by Eset about heuristics. Very informative, you might want to retrieve it and read it 'heuristic analysis - detecting unknown viruses'

The 99 % I mentioned (Avira) includes the use of heuristics (see av-comparatives).

Some things that heuristics usually don't include: virtual sandbox, HIPS, Kaspersky's program control (not the exact name, I don't recall) etc.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:45 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums