Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 12th, 2010, 08:45 AM
Jeroen1000 Jeroen1000 is offline
Regular Poster
 
Join Date: Aug 2008
Posts: 159
Default Prevx heuristics adjustments vs false positives

I've been wondering for some time about this now, please enlighten me

Sometimes, Prevx sees a FP because a "definition" has become too heuristic. Fine, this can be fixed quickly. However, is it possible that real virusses that were previously detected are missed since the heuristic detection rule has been altered?
  #2  
Old April 12th, 2010, 09:12 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,578
Default Re: Prevx heuristics adjustments vs false positives

Quote:
Originally Posted by Jeroen1000
I've been wondering for some time about this now, please enlighten me

Sometimes, Prevx sees a FP because a "definition" has become too heuristic. Fine, this can be fixed quickly. However, is it possible that real virusses that were previously detected are missed since the heuristic detection rule has been altered?

When we fix a FP, it generally could tune down the heuristics slightly for other files as well, but at that point we're able to see exactly what component of the rule caused the FP and because of our database, we're able to see exactly how many files would be affected by it, so we are able to make very fine-tuned adjustments On the other side, however, we have some rules which find 300,000+ infections from a single heuristic and have produced 3-4 FPs. In that case, we just whitelist the individual files

Hope that helps!
  #3  
Old April 12th, 2010, 10:05 AM
Jeroen1000 Jeroen1000 is offline
Regular Poster
 
Join Date: Aug 2008
Posts: 159
Default Re: Prevx heuristics adjustments vs false positives

Thanks Joe, I have been educated I was just a tad worried that detection might get worse whenever a rule is adjusted because of an FP. Although you do not exclude that scenario, I feel at ease by the way you go about it.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:26 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums